CVE Feed

    Dashboard / CVE / CVE-2022-27226

    CVE-2022-27226

    A CSRF issue in /api/crontab on iRZ Mobile Routers through 2022-03-16 allows a threat actor to create a crontab entry in the router administration panel. The cronjob will consequently execute the entry on the threat actor's defined interval, leading to remote code execution, allowing the threat actor to gain filesystem access. In addition, if the router's default credentials aren't rotated or a threat actor discovers valid credentials, remote code execution can be achieved without user interaction.

    Published:Mar 19, 2022
    Last Modified:Nov 21, 2024
    EPS:Mar 19, 2022
    EPSS Score:0.02536
    CVSS Score:8.8

    Affected Products

    Vendor
    Irz
    Product
    Rl01
    Vendor
    Irz
    Product
    Rl01 Firmware
    Vendor
    Irz
    Product
    Rl21
    Vendor
    Irz
    Product
    Rl21 Firmware
    Vendor
    Irz
    Product
    Ru21
    Vendor
    Irz
    Product
    Ru21 Firmware
    Vendor
    Irz
    Product
    Ru21w
    Vendor
    Irz
    Product
    Ru21w Firmware
    Vendor
    Irz
    Product
    Ru41
    Vendor
    Irz
    Product
    Ru41 Firmware

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High