peter bassill · operator
$ cve CVE-2022-32765 JSON

CVE-2022-32765

9.8
CRITICAL · CVSS 3.1 · EPSS 3.6% (pctl 89)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

An OS command injection vulnerability exists in the sysupgrade command injection functionality of Robustel R1510 3.1.16 and 3.3.0. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger this vulnerability.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.62% — more likely to be exploited than 89% of all CVEs
WeaknessCWE-77
On CISA KEVno
Public exploitnone known
Published2022-10-25
Last modified2026-06-17

Affected (2)

VendorProduct
robustelr1510
robustelr1510 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD