CVE-2022-45701

HIGH

Commscope Arris Tg2482a Firmware < 9.1.103 - Command Injection

Title source: rule

Description

Arris TG2482A firmware through 9.1.103GEM9 allow Remote Code Execution (RCE) via the ping utility feature.

Exploits (4)

exploitdb WORKING POC
by Yerodin Richards · pythonremotehardware
https://www.exploit-db.com/exploits/51269
nomisec WORKING POC 7 stars
by yerodin · poc
https://github.com/yerodin/CVE-2022-45701
nomisec WORKING POC 5 stars
by geniuszly · poc
https://github.com/geniuszly/CVE-2022-45701
inthewild WORKING POC
poc
https://github.com/geniuszlyy/cve-2022-45701

Scores

CVSS v3 8.8
EPSS 0.3884
EPSS Percentile 97.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-77
Status published
Products (3)
commscope/arris_sbg10_firmware < 9.1.103
commscope/arris_tg2482a_firmware < 9.1.103
commscope/arris_tg2492_firmware < 9.1.103
Published Feb 17, 2023
Tracked Since Feb 18, 2026