CVE-2022-27226
Summary
| CVE | CVE-2022-27226 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-03-19 04:15:00 UTC |
| Updated | 2022-03-28 19:13:00 UTC |
| Description | A CSRF issue in /api/crontab on iRZ Mobile Routers through 2022-03-16 allows a threat actor to create a crontab entry in the router administration panel. The cronjob will consequently execute the entry on the threat actor's defined interval, leading to remote code execution, allowing the threat actor to gain filesystem access. In addition, if the router's default credentials aren't rotated or a threat actor discovers valid credentials, remote code execution can be achieved without user interaction. |
Risk And Classification
Problem Types: CWE-352
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Irz | Rl01 | - | All | All | All |
| Operating System | Irz | Rl01 Firmware | All | All | All | All |
| Hardware | Irz | Rl21 | - | All | All | All |
| Operating System | Irz | Rl21 Firmware | All | All | All | All |
| Hardware | Irz | Ru21 | - | All | All | All |
| Hardware | Irz | Ru21w | - | All | All | All |
| Operating System | Irz | Ru21w Firmware | All | All | All | All |
| Operating System | Irz | Ru21 Firmware | All | All | All | All |
| Hardware | Irz | Ru41 | - | All | All | All |
| Operating System | Irz | Ru41 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| iRZ Mobile Router Cross Site Request Forgery / Remote Code Execution ≈ Packet Storm | MISC | packetstormsecurity.com | |
| John J Hacking | MISC | johnjhacking.com | |
| Izhevskiy radiozavod | MISC | en.irz.ru | |
| GitHub - SakuraSamuraii/ez-iRZ: Exploit for CVE-2022-27226 | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.