PT-2022-24037 · Smartrg · Smartrg Sr510N+1
Yerodin Richards
·
Published
2022-09-14
·
Updated
2023-01-20
·
CVE-2022-37661
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SmartRG SR506n version 2.5.15
SmartRG SR510n version 2.6.13
Description
The issue allows for Remote Code Execution (RCE) via the ping host feature.
Recommendations
For SmartRG SR506n version 2.5.15, consider disabling the ping host feature until a patch is available.
For SmartRG SR510n version 2.6.13, consider disabling the ping host feature until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Smartrg Sr506N
Smartrg Sr510N