9.8
CVSSv3

CVE-2021-22646

Published: 28/07/2022 Updated: 04/08/2022
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

The “ipk” package containing the configuration created by TWinSoft can be uploaded, extracted, and executed in Ovarro TBox, allowing malicious code execution.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ovarro twinsoft

ovarro tbox_lt2-530_firmware

ovarro tbox_lt2-532_firmware

ovarro tbox_lt2-540_firmware

ovarro tbox_ms-cpu32_firmware

ovarro tbox_ms-cpu32-s2_firmware

ovarro tbox_rm2_firmware

ovarro tbox_tg2_firmware