go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Realtek GPON router - Command Injection

TVN ID TVN-202212004
CVE ID CVE-2022-40740
CVSS 7.2 (High)
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected Products Realtek GPON router SDK 1.9
Description Realtek GPON router has insufficient filtering for special characters. A remote attacker authenticated as an administrator can exploit this vulnerability to perform command injection attacks, to execute arbitrary system command, manipulate system or disrupt service.
Solution Contact tech support from Realtek
Credit Realtek
Public Date 2022-12-30
Top