CVE-2022-37070: OS Command Injection
Published Aug 25, 2022
·Updated
H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a command injection vulnerability via the param parameter at DelL2tpLNSList.
Affected Software
2 affected components
H3C Gr-1200w Firmware<=minigrw1a0v100r006
H3C GR-1200W
Event History
Aug 25, 2022
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is CVE-2022-37070?
CVE-2022-37070 refers to a command injection vulnerability found in the H3C GR-1200W MiniGRW1A0V100R006 firmware.
2
What is the severity of CVE-2022-37070?
CVE-2022-37070 has a severity rating of 9.8 (Critical).
3
How does CVE-2022-37070 impact H3C GR-1200W MiniGRW1A0V100R006?
CVE-2022-37070 allows attackers to execute arbitrary commands on the affected device through the "param" parameter at DelL2tpLNSList.
4
Is H3C GR-1200W MiniGRW1A0V100R006 the only affected software?
Yes, H3C GR-1200W MiniGRW1A0V100R006 firmware is the only affected software.
5
How can I fix CVE-2022-37070?
To fix CVE-2022-37070, it is recommended to update to a patched version of the H3C GR-1200W firmware.