PT-2022-22672 · Robustel · Robustel R1510

Francesco Benvenuto

·

Published

2022-10-25

·

Updated

2023-02-24

·

CVE-2022-35269

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Robustel R1510 versions 3.1.16 through 3.3.0
Description A denial of service issue exists in the web server hashFirst functionality. A specially-crafted network request can lead to denial of service. An attacker can send a sequence of requests to trigger this issue. The /action/import e2c json file/ API endpoint is affected.
Recommendations For versions 3.1.16 and 3.3.0, consider disabling access to the /action/import e2c json file/ API endpoint as a temporary workaround until a patch is available. Restricting the hashFirst functionality in the web server may also help minimize the risk of exploitation.

Exploit

Fix

Out of bounds Read

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2022-35269

Affected Products

Robustel R1510