CVE-2021-22646
28.07.2022, 15:15
The ipk package containing the configuration created by TWinSoft can be uploaded, extracted, and executed in Ovarro TBox, allowing malicious code execution.
Vendor | Product | Version |
---|---|---|
ovarro | twinsoft | 𝑥 < 12.4 |
ovarro | tbox_lt2-530_firmware | 𝑥 < 1.46 |
ovarro | tbox_lt2-532_firmware | 𝑥 < 1.46 |
ovarro | tbox_lt2-540_firmware | 𝑥 < 1.46 |
ovarro | tbox_ms-cpu32_firmware | 𝑥 < 1.46 |
ovarro | tbox_ms-cpu32-s2_firmware | 𝑥 < 1.46 |
ovarro | tbox_rm2_firmware | 𝑥 < 1.46 |
ovarro | tbox_tg2_firmware | 𝑥 < 1.46 |
𝑥
= Vulnerable software versions