VulnerabilityModified
CVE-2022-37661
SmartRG SR506n 2.5.15 and SR510n 2.6.13 routers are vulnerable to Remote Code Execution (RCE) via the ping host feature.
CRITICAL 9.8EPSS 33.9%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 33.9%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
SmartRG SR506n 2.5.15 and SR510n 2.6.13 routers are vulnerable to Remote Code Execution (RCE) via the ping host feature.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 33.87% probability · 98th percentile
- CISA KEV
- Not listed
- Affected
- adtran/sr510n firmware · adtran/sr506n firmware
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/168336/SmartRG-Router-2.6.13-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/169816/SmartRG-Router-SR510n-2.6.13-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://cxsecurity.com/issue/WLB-2022090029Exploit, Third Party Advisory
- https://packetstormsecurity.com/files/cve/CVE-2022-37661Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/168336/SmartRG-Router-2.6.13-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/169816/SmartRG-Router-SR510n-2.6.13-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://cxsecurity.com/issue/WLB-2022090029Exploit, Third Party Advisory
- https://packetstormsecurity.com/files/cve/CVE-2022-37661Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.