CVE-2022-22986: OS Command Injection
Published Mar 31, 2022
·Updated
Netcommunity OG410X and OG810X series (Netcommunity OG410Xa, OG410Xi, OG810Xa, and OG810Xi firmware Ver.2.28 and earlier) allow an attacker on the adjacent network to execute an arbitrary OS command via a specially crafted config file.
Affected Software
8 affected components
Ntt-east Og410xa Firmware<=2.28
Ntt-east Og410xa
Ntt-east Og410xi Firmware<=2.28
Ntt-east Og410xi
Ntt-east Og810xa Firmware<=2.28
Ntt-east Og810xa
Ntt-east Og810xi Firmware<=2.28
Ntt-east Og810xi
Event History
Mar 31, 2022
CVE Published
via MITRE·07:20 AM
Data Sourced
via MITRE·07:20 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-22986.
2
What is the severity of CVE-2022-22986?
The severity of CVE-2022-22986 is high with a CVSS score of 8.8.
3
Which software versions are affected by CVE-2022-22986?
Netcommunity OG410Xa, OG410Xi, OG810Xa, and OG810Xi firmware versions up to 2.28 are affected.
4
How can an attacker exploit CVE-2022-22986?
An attacker on the adjacent network can execute an arbitrary OS command via a specially crafted config file.
5
Is there a fix available for CVE-2022-22986?
It is recommended to update the Netcommunity OG410X and OG810X series firmware to version 2.29 or later to mitigate the vulnerability.