PT-2022-4623 · Centrecom · Centrecom Ar260S V2

Chuya Hayakawa

·

Published

2022-08-29

·

Updated

2022-09-13

·

CVE-2022-34869

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CentreCOM AR260S V2 firmware versions prior to Ver.3.3.7
Description The issue is related to an undocumented hidden command that can be executed from the telnet function, allowing a remote authenticated attacker to execute an arbitrary OS command. This can potentially allow an attacker to elevate their privileges.
Recommendations For CentreCOM AR260S V2 firmware versions prior to Ver.3.3.7, update to a version that is Ver.3.3.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the telnet function until a patch is available.

Fix

Hidden Functionality

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-05504
CVE-2022-34869

Affected Products

Centrecom Ar260S V2