9.8
CVSSv3

CVE-2022-26999

Published: 15/03/2022 Updated: 08/08/2023
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Arris TR3300 v1.0.13 exists to contain a command injection vulnerability in the static ip settings function via the wan_ip_stat, wan_mask_stat, wan_gw_stat, and wan_dns1_stat parameters. This vulnerability allows malicious users to execute arbitrary commands via a crafted request.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

commscope arris_tr3300_firmware 1.0.13