Xspeeder SXZOS through 2025-12-26 allows root remote code...
Critical severity
Unreviewed
Published
Dec 27, 2025
to the GitHub Advisory Database
•
Updated Jan 9, 2026
Description
Published by the National Vulnerability Database
Dec 27, 2025
Published to the GitHub Advisory Database
Dec 27, 2025
Last updated
Jan 9, 2026
Xspeeder SXZOS through 2025-12-26 allows root remote code execution via base64-encoded Python code in the chkid parameter to vLogin.py. The title and oIP parameters are also used.
References