PT-2022-3891 · Robustel · Robustel R1510

Francesco Benvenuto

·

Published

2022-06-14

·

Updated

2022-10-13

·

CVE-2022-33329

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Robustel R1510 version 3.3.0
Description The issue is related to command injection vulnerabilities in the web server's ajax endpoints functionalities. A specially-crafted network packet can lead to arbitrary command execution. The /ajax/set sys time/ API endpoint is affected by a command injection vulnerability. This vulnerability is due to the lack of neutralization of special elements used in the operating system command, which can be exploited by sending specially-crafted requests to execute arbitrary commands.
Recommendations For Robustel R1510 version 3.3.0, consider disabling the /ajax/set sys time/ API endpoint until a patch is available to prevent exploitation of the command injection vulnerability. Restrict access to the set sys time functionality to minimize the risk of exploitation. Avoid using the set sys time function until the issue is resolved.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2022-04701
CVE-2022-33329

Affected Products

Robustel R1510