PT-2022-28036 · NetGear · Rax30 Firmware

Published

2022-12-16

·

Updated

2023-08-08

·

CVE-2022-47210

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions No specific software or versions are mentioned in the provided descriptions.
Description The default console presented to users over telnet, when enabled, is restricted to a subset of commands. However, commands issued at this console appear to be fed directly into a system call or other similar function, allowing any authenticated user to execute arbitrary commands on the device.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2022-47210

Affected Products

Rax30 Firmware