PT-2022-22672 · Robustel · Robustel R1510
Francesco Benvenuto
·
Published
2022-10-25
·
Updated
2023-02-24
·
CVE-2022-35269
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Robustel R1510 versions 3.1.16 through 3.3.0
Description
A denial of service issue exists in the web server hashFirst functionality. A specially-crafted network request can lead to denial of service. An attacker can send a sequence of requests to trigger this issue. The
/action/import e2c json file/ API endpoint is affected.Recommendations
For versions 3.1.16 and 3.3.0, consider disabling access to the
/action/import e2c json file/ API endpoint as a temporary workaround until a patch is available. Restricting the hashFirst functionality in the web server may also help minimize the risk of exploitation.Exploit
Fix
Out of bounds Read
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Robustel R1510