Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-68533
HistoryMar 17, 2022 - 12:00 a.m.

Multiple ARRIS Product Command Injection Vulnerabilities (CNVD-2022-68533)

2022-03-1700:00:00
China National Vulnerability Database
www.cnvd.org.cn
8
arris
wi-fi routers
command injection
vulnerability
pppoe function
arbitrary command execution

EPSS

0.002

Percentile

52.4%

ARRIS SBR-AC1900P, SBR-AC3200P and SBR-AC1200P is a Wi-Fi router from ARRIS, Inc. Multiple ARRIS products are vulnerable to a command injection vulnerability, which stems from the pppoeUserName, pppoePassword, and pppoe_Service parameters in the pppoe function failing to properly filter the construct command special characters, commands, etc. An attacker could use this vulnerability to cause arbitrary command execution.

EPSS

0.002

Percentile

52.4%