Remote Command Injection in Belkin N300 Firmware
CVE-2022-30105

9.8CRITICAL

Key Information:

Vendor

Belkin

Vendor
CVE Published:
18 May 2022

What is CVE-2022-30105?

The Belkin N300 Firmware 1.00.08 contains multiple remote command injection vulnerabilities in its web interface located at /setting_hidden.asp. These vulnerabilities arise from improper sanitization of parameters in the web form, allowing attackers to send specially crafted POST requests that can execute arbitrary OS commands with root privileges. Given that the web interface and associated processes operate as root, successful exploitation could lead to complete device control, potentially compromising network security.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.