CVE-2022-26991: OS Command Injection
Arris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection vulnerability in the ntp function via the TimeZone parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-26991?
CVE-2022-26991 is a command injection vulnerability in Arris routers SBR-AC1900P, SBR-AC3200P, and SBR-AC1200P.
How severe is CVE-2022-26991?
CVE-2022-26991 has a severity rating of 9.8 (Critical).
Which routers are affected by CVE-2022-26991?
Arris routers SBR-AC1900P, SBR-AC3200P, and SBR-AC1200P are affected by CVE-2022-26991.
How can an attacker exploit CVE-2022-26991?
An attacker can exploit CVE-2022-26991 by sending a crafted request to the ntp function via the TimeZone parameter, allowing for the execution of arbitrary commands.
Is there a fix available for CVE-2022-26991?
At the moment, there is no known fix for CVE-2022-26991. It is recommended to contact the vendor for further information or mitigation steps.