The “puhttpsniff” service, which runs by default, is susceptible to command injection due to improperly sanitized user input. An unauthenticated attacker on the same network segment as the router can execute arbitrary commands on the device without authentication.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.tenable.com/security/research/tra-2022-37 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: tenable
Published: 2022-12-16T00:00:00
Updated: 2024-08-03T14:47:29.421Z
Reserved: 2022-12-12T00:00:00
Link: CVE-2022-47208
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-12-16T20:15:08.860
Modified: 2024-11-21T07:31:41.610
Link: CVE-2022-47208
Redhat
No data.