github.com
https://github.com/wudipjq/my_vuln/blob/main/ARRIS/vuln_10/10.md CVE-2022-27002
CRITICAL
commscope arris_tr3300_firmware Improper Neutralization of Special Elements used in a Command ('Command Injection')
Record summary
CVE-2022-27002 has a selected CVSS score of 9.8 (critical).
Description
Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the ddns function via the ddns_name, ddns_pwd, h_ddns、ddns_host parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jun 22, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
arris_tr3300_firmwareBrowse commscope / arris_tr3300_firmware | VulnCheck | Version data not supplied | |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-27002