CVE-2022-37661
CRITICAL EXPLOITEDSmartRG SR506n 2.5.15 and SR510n 2.6.13 - Remote Code Execution via Ping Host Feature
Title source: llmExploitation Summary
CVE-2022-37661 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including Yerodin Richards.
AI-analyzed exploit summary This exploit targets a command injection vulnerability in SmartRG routers (CVE-2022-37661) by leveraging the ping functionality to execute arbitrary commands. It establishes a reverse shell via netcat after extracting a session key from the router's admin interface.
Description
SmartRG SR506n 2.5.15 and SR510n 2.6.13 routers are vulnerable to Remote Code Execution (RCE) via the ping host feature.
Exploits (1)
This exploit targets a command injection vulnerability in SmartRG routers (CVE-2022-37661) by leveraging the ping functionality to execute arbitrary commands. It establishes a reverse shell via netcat after extracting a session key from the router's admin interface.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H