A vulnerability, which was classified as critical , has been found in seriousm4x UpSnap up to 5.3.x . Affected by this issue is some unknown functionality of the component Device Management . Performing a manipulation of the argument ip/mac results in os command injection. This vulnerability was named CVE-2026-49481 . The attack may be initiated remotely. There is no available exploit. It is advisable to upgrade the affected component.