CVE-2022-26995: Command Injection
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the pptp (wanpptp.html) function via the pptpfixip, pptpfixmask, pptpfixgw, and wandns1stat parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-26995?
CVE-2022-26995 is a command injection vulnerability in the Arris TR3300 v1.0.13 router.
What is the severity of CVE-2022-26995?
The severity of CVE-2022-26995 is critical with a CVSS score of 9.8.
How does CVE-2022-26995 affect Arris TR3300 v1.0.13?
CVE-2022-26995 allows attackers to execute arbitrary commands via a crafted request in the pptp function.
Is Commscope Arris Tr3300 vulnerable to CVE-2022-26995?
Yes, Commscope Arris Tr3300 firmware version 1.0.13 is vulnerable to CVE-2022-26995.
How can I fix CVE-2022-26995 on Arris TR3300 v1.0.13?
There is no known fix for CVE-2022-26995 at the moment. It is recommended to contact the vendor for updates or mitigation measures.