CVE-2022-27001: Command Injection
Published Mar 15, 2022
·Updated
Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the dhcp function via the hostname parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
Affected Software
2 affected components
CommScope Arris Tr3300 Firmware=1.0.13
CommScope Arris Tr3300
Event History
Mar 15, 2022
CVE Published
via MITRE·09:56 PM
Data Sourced
via MITRE·09:56 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-27001?
The severity of CVE-2022-27001 is critical with a CVSS score of 9.8.
2
What is the affected software for CVE-2022-27001?
The affected software for CVE-2022-27001 is Commscope Arris Tr3300 Firmware version 1.0.13.
3
How does CVE-2022-27001 affect the Arris TR3300 router?
CVE-2022-27001 allows attackers to execute arbitrary commands via a crafted request in the dhcp function of the Arris TR3300 router.
4
How can I fix CVE-2022-27001?
To fix CVE-2022-27001, it is recommended to update the firmware of the Arris TR3300 router to a version that has the vulnerability patched.
5
Is the Commscope Arris Tr3300 vulnerable to CVE-2022-27001?
No, the Commscope Arris Tr3300 is not vulnerable to CVE-2022-27001.