peter bassill · operator
$ cve CVE-2022-27226 JSON

CVE-2022-27226 EXPLOIT

8.8
HIGH · CVSS 3.1 · EPSS 33.7% (pctl 98)

Patch early

A public exploit exists.

Description

A CSRF issue in /api/crontab on iRZ Mobile Routers through 2022-03-16 allows a threat actor to create a crontab entry in the router administration panel. The cronjob will consequently execute the entry on the threat actor's defined interval, leading to remote code execution, allowing the threat actor to gain filesystem access. In addition, if the router's default credentials aren't rotated or a threat actor discovers valid credentials, remote code execution can be achieved without user interaction.

Scoring

CVSS8.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS33.7% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-352
On CISA KEVno
Public exploityes
Published2022-03-19
Last modified2026-06-17

Affected (10)

VendorProduct
irzrl01
irzrl01 firmware
irzrl21
irzrl21 firmware
irzru21
irzru21 firmware
irzru21w
irzru21w firmware
irzru41
irzru41 firmware

Public exploits

SourceTitleDate
exploit-dbiRZ Mobile Router - CSRF to RCE2022-03-22

References

→ the Explorer  ·  watch your stack  ·  NVD