PT-2022-18169 · Arris · Sbr-Ac1900P+2

CVE-2022-26993

·

Published

2022-03-15

·

Updated

2023-08-08

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Arris routers SBR-AC1900P version 1.0.7-B05 Arris routers SBR-AC3200P version 1.0.7-B05 Arris routers SBR-AC1200P version 1.0.5-B05
Description A command injection issue was discovered in the pppoe function, allowing attackers to execute arbitrary commands via a crafted request. The vulnerability is exploited through the pppoeUserName, pppoePassword, and pppoe Service parameters.
Recommendations For Arris routers SBR-AC1900P version 1.0.7-B05, consider disabling the pppoe function until a patch is available. For Arris routers SBR-AC3200P version 1.0.7-B05, restrict access to the pppoe function to minimize the risk of exploitation. For Arris routers SBR-AC1200P version 1.0.5-B05, avoid using the pppoeUserName, pppoePassword, and pppoe Service parameters in the affected API endpoint until the issue is resolved.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-26993

Affected Products

Sbr-Ac1200P
Sbr-Ac1900P
Sbr-Ac3200P