CVE-2022-36779
MEDIUMProscend M330-W/M330-W5/M350-5G/M350-W5G/M350-6/M350-W6/M301-G/M301-GW & ADVICE ICR-111WG - OS Command Injection
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2022-36779. PoCs published by rootDR, rootdr-backup, EmadYaY.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2022-36779, an authenticated command injection vulnerability. The Python script authenticates with default credentials and allows arbitrary command execution via a vulnerable CGI endpoint.
Description
PROSCEND - PROSCEND / ADVICE .Ltd - G/5G Industrial Cellular Router (with GPS)4 Unauthenticated OS Command Injection Proscend M330-w / M33-W5 / M350-5G / M350-W5G / M350-6 / M350-W6 / M301-G / M301-GW ADVICE ICR 111WG / https://www.proscend.com/en/category/industrial-Cellular-Router/industrial-Cellular-Router.html https://cdn.shopify.com/s/files/1/0036/9413/3297/files/ADVICE_Industrial_4G_LTE_Cellular_Router_ICR111WG.pdf?v=1620814301
Exploits (3)
This repository contains a functional exploit for CVE-2022-36779, an authenticated command injection vulnerability. The Python script authenticates with default credentials and allows arbitrary command execution via a vulnerable CGI endpoint.
This repository contains a functional exploit for CVE-2022-36779, an authenticated command injection vulnerability. The script authenticates with default credentials and allows arbitrary command execution via a vulnerable CGI endpoint.
This repository contains a functional exploit for CVE-2022-36779, an unauthenticated OS command injection vulnerability in Proscend Industrial Cellular Router. The exploit authenticates with default credentials and allows arbitrary command execution via a crafted request to `/cgi-bin/popen.cgi`.
References (1)
Scores
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L