CVE-2022-22986
Netcommunity OG410X and OG810X series (Netcommunity OG410Xa, OG410Xi, OG810Xa, and OG810Xi firmware Ver.2.28 and earlier) allow an attacker on the adjacent network to execute an arbitrary OS command via a specially crafted config file.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.74%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Netcommunity OG410X and OG810X series (Netcommunity OG410Xa, OG410Xi, OG810Xa, and OG810Xi firmware Ver.2.28 and earlier) allow an attacker on the adjacent network to execute an arbitrary OS command via a specially crafted config file.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.74% probability · 53th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- ntt-east/og410xa firmware · ntt-east/og410xi firmware · ntt-east/og810xa firmware · ntt-east/og810xi firmware
- Source
- vultures@jpcert.or.jp
References
- https://business.ntt-east.co.jp/topics/2022/03_22.htmlVendor Advisory
- https://jvn.jp/en/vu/JVNVU94900322/index.htmlThird Party Advisory, VDB Entry
- https://www.ntt-west.co.jp/smb/kiki_info/info/220322.htmlVendor Advisory
- https://business.ntt-east.co.jp/topics/2022/03_22.htmlVendor Advisory
- https://jvn.jp/en/vu/JVNVU94900322/index.htmlThird Party Advisory, VDB Entry
- https://www.ntt-west.co.jp/smb/kiki_info/info/220322.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.