CVE-2022-26996: Command Injection
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the pppoe function via the pppoeusername, pppoepasswd, and pppoeservicename parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-26996?
CVE-2022-26996 is a command injection vulnerability in Arris TR3300 v1.0.13.
How severe is CVE-2022-26996?
CVE-2022-26996 has a severity rating of 9.8 (Critical).
What software versions are affected by CVE-2022-26996?
Arris TR3300 v1.0.13 is affected by CVE-2022-26996.
How can an attacker exploit CVE-2022-26996?
Attackers can exploit CVE-2022-26996 by executing arbitrary commands through crafted requests in the pppoe function using pppoe_username, pppoe_passwd, and pppoe_servicename parameters.
Are there any references available for CVE-2022-26996?
Yes, you can find more information about CVE-2022-26996 at the following reference: https://github.com/wudipjq/my_vuln/blob/main/ARRIS/vuln_13/13.md.