CVE-2022-44606
OS command injection vulnerability in UDR-JA1604/UDR-JA1608/UDR-JA1616 firmware versions 71x10.1.107112.43A and earlier allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter the device settings.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.47%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
OS command injection vulnerability in UDR-JA1604/UDR-JA1608/UDR-JA1616 firmware versions 71x10.1.107112.43A and earlier allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter the device settings.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.47% probability · 72th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- unimo/udr-ja1604 firmware · unimo/udr-ja1608 firmware · unimo/udr-ja1616 firmware
- Source
- vultures@jpcert.or.jp
References
- http://www.unimo.co.jp/table_notice/index.php?act=1&resid=1666831567-004418Vendor Advisory
- https://jvn.jp/en/vu/JVNVU94514762/index.htmlThird Party Advisory
- http://www.unimo.co.jp/table_notice/index.php?act=1&resid=1666831567-004418Vendor Advisory
- https://jvn.jp/en/vu/JVNVU94514762/index.htmlThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.