CVE-2022-26997: Command Injection
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the upnp function via the upnpttl parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this command injection vulnerability?
The vulnerability ID for this command injection vulnerability is CVE-2022-26997.
What is the affected software for this vulnerability?
The affected software for this vulnerability is Commscope Arris Tr3300 firmware version 1.0.13.
What is the severity of CVE-2022-26997?
The severity of CVE-2022-26997 is critical with a severity value of 9.8.
How can an attacker exploit CVE-2022-26997?
An attacker can exploit CVE-2022-26997 by sending a crafted request with a malicious upnp_ttl parameter, allowing them to execute arbitrary commands.
Is there a fix available for CVE-2022-26997?
At the moment, there is no information available about a fix for CVE-2022-26997. It is recommended to follow the reference link for any updates or security patches.