PT-2022-2960 · Unknown · Irz Mobile Routers
Chris Mack
+1
·
Published
2022-03-19
·
Updated
2022-04-14
·
CVE-2022-27226
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
iRZ Mobile Routers through 2022-03-16
Description
A CSRF issue in "/api/crontab" allows a threat actor to create a crontab entry in the router administration panel. The cronjob will execute the entry on the threat actor's defined interval, leading to remote code execution and filesystem access. If the router's default credentials are not rotated or a threat actor discovers valid credentials, remote code execution can be achieved without user interaction.
Recommendations
For iRZ Mobile Routers through 2022-03-16, consider disabling access to the "/api/crontab" endpoint until a patch is available. Additionally, ensure that default credentials are rotated and secure credentials are used to prevent remote code execution without user interaction. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Irz Mobile Routers