9.8
CVSSv3

CVE-2022-39073

Published: 06/01/2023 Updated: 12/01/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

There is a command injection vulnerability in ZTE MF286R, Due to insufficient validation of the input parameters, an attacker could use the vulnerability to execute arbitrary commands.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zte mf286r_firmware nordic_mf286r_b06

Github Repositories

Proof of concept for the command injection vulnerability affecting the ZTE MF286R router, including an RCE exploit.

CVE-2022-39073 Firmware details: wa_inner_version: BD_POSTEMF286RMODULEV100B12 cr_version: CR_ITPOSTEMF286RV100B10 Prerequisites requests (pip install requests) Command Injection The vulnerability is a shared command injection between the zte_net_link_detect binary and the WATCH_DOG_SWITCH handler in the webserver goahead binary No