CVE-2022-40740

Realtek GPON router has insufficient filtering for special characters. A remote attacker authenticated as an administrator can exploit this vulnerability to perform command injection attacks, to execute arbitrary system command, manipulate system or disrupt service.
References
Link Resource
https://www.twcert.org.tw/tw/cp-132-6831-19121-1.html Third Party Advisory VDB Entry
https://www.twcert.org.tw/tw/cp-132-6831-19121-1.html Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:realtek:usdk:1.0:*:*:*:*:*:*:*
cpe:2.3:a:realtek:usdk:2.0:*:*:*:*:*:*:*
cpe:2.3:a:realtek:usdk:2.2:*:*:*:*:*:*:*
cpe:2.3:a:realtek:xpon_software_development_kit:1.9:*:*:*:*:*:*:*
cpe:2.3:a:realtek:xpon_software_development_kit:3.3:*:*:*:*:*:*:*
cpe:2.3:a:realtek:xpon_software_development_kit:4.0:*:*:*:*:*:*:*
cpe:2.3:a:realtek:xpon_software_development_kit:4.1:*:*:*:*:*:*:*

History

21 Nov 2024, 07:21

Type Values Removed Values Added
References () https://www.twcert.org.tw/tw/cp-132-6831-19121-1.html - Third Party Advisory, VDB Entry () https://www.twcert.org.tw/tw/cp-132-6831-19121-1.html - Third Party Advisory, VDB Entry
Summary
  • (es) El router Realtek GPON tiene un filtrado insuficiente para caracteres especiales. Un atacante remoto autenticado como administrador puede aprovechar esta vulnerabilidad para realizar ataques de inyección de comandos, ejecutar comandos arbitrarios del sistema, manipular el sistema o interrumpir el servicio.

10 Jul 2023, 18:48

Type Values Removed Values Added
CWE CWE-78 NVD-CWE-Other

Information

Published : 2023-01-03 03:15

Updated : 2024-11-21 07:21


NVD link : CVE-2022-40740

Mitre link : CVE-2022-40740

CVE.ORG link : CVE-2022-40740


JSON object : View

Products Affected

realtek

  • xpon_software_development_kit
  • usdk
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

NVD-CWE-Other