PT-2022-18178 · Arris · Arris Tr3300

Published

2022-03-15

·

Updated

2023-08-08

·

CVE-2022-27001

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Arris TR3300 version 1.0.13
Description A command injection issue was found in the dhcp function via the hostname parameter, allowing attackers to execute arbitrary commands through a crafted request.
Recommendations For Arris TR3300 version 1.0.13, as a temporary workaround, consider restricting access to the dhcp function to minimize the risk of exploitation. Avoid using the hostname parameter in the affected function until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2022-27001

Affected Products

Arris Tr3300