CVE-2022-26999: Command Injection
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the static ip settings function via the wanipstat, wanmaskstat, wangwstat, and wandns1stat parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-26999?
CVE-2022-26999 is a command injection vulnerability in Arris TR3300 v1.0.13 router firmware.
How severe is CVE-2022-26999?
CVE-2022-26999 has a severity rating of 9.8, which is considered critical.
How does CVE-2022-26999 affect Arris TR3300 v1.0.13?
CVE-2022-26999 allows attackers to execute arbitrary commands on the affected Arris TR3300 v1.0.13 router firmware.
Is Commscope Arris Tr3300 affected by CVE-2022-26999?
Only the Arris TR3300 v1.0.13 firmware is affected by CVE-2022-26999; the Commscope Arris Tr3300 hardware itself is not vulnerable.
How can I fix CVE-2022-26999?
To fix CVE-2022-26999, you should update the Arris TR3300 firmware to a version that patches the command injection vulnerability.