CVE-2022-26994
15.03.2022, 22:15
Arris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection vulnerability in the pptp function via the pptpUserName and pptpPassword parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
Vendor | Product | Version |
---|---|---|
arris | sbr-ac1900p_firmware | 1.0.7-b05 |
arris | sbr-ac3200p_firmware | 1.0.7-b05 |
arris | sbr-ac1200p_firmware | 1.0.5-b05 |
𝑥
= Vulnerable software versions