CVE-2022-27000: Command Injection
Published Mar 15, 2022
·Updated
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the time and time zone function via the hprimaryntpserver, hbackupntpserver, and htimezone parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
Affected Software
2 affected components
CommScope Arris Tr3300 Firmware=1.0.13
CommScope Arris Tr3300
Event History
Mar 15, 2022
CVE Published
via MITRE·09:56 PM
Data Sourced
via MITRE·09:56 PM
Description
Frequently Asked Questions
1
What is CVE-2022-27000?
CVE-2022-27000 is a command injection vulnerability in Arris TR3300 v1.0.13.
2
How does CVE-2022-27000 affect Arris TR3300?
CVE-2022-27000 allows attackers to execute arbitrary commands on Arris TR3300 v1.0.13.
3
What is the severity of CVE-2022-27000?
CVE-2022-27000 has a severity value of 9.8, which is considered critical.
4
How can I fix CVE-2022-27000?
To fix CVE-2022-27000, update to a version of Arris TR3300 firmware that is not affected.
5
Is Commscope Arris Tr3300 affected by CVE-2022-27000?
No, Commscope Arris Tr3300 is not affected by CVE-2022-27000.