PT-2022-23431 · H3C · H3C Gr-3200

Published

2022-08-25

·

Updated

2025-06-17

·

CVE-2022-36509

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions H3C GR3200 MiniGR1B0V100R014
Description A command injection issue was discovered via the param parameter at DelL2tpLNSList.
Recommendations For H3C GR3200 MiniGR1B0V100R014, consider restricting access to the DelL2tpLNSList to minimize the risk of exploitation. Avoid using the param parameter in the affected endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2022-36509

Affected Products

H3C Gr-3200