CVE-2022-27002: Command Injection
Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the ddns function via the ddnsname, ddnspwd, hddns、ddnshost parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
Other sources
Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the ddns function via the ddnsname, ddnspwd, hddns?ddnshost parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2022-27002.
What is the severity of CVE-2022-27002?
The severity of CVE-2022-27002 is critical.
How does CVE-2022-27002 affect Arris TR3300 v1.0.13?
CVE-2022-27002 affects Arris TR3300 v1.0.13 by allowing attackers to execute arbitrary commands via a crafted request.
Which software version is affected by CVE-2022-27002?
The software version affected by CVE-2022-27002 is Arris TR3300 v1.0.13.
Is Commscope Arris Tr3300 vulnerable to CVE-2022-27002?
No, Commscope Arris Tr3300 is not vulnerable to CVE-2022-27002.