Command Injection Vulnerability in H3C GR-1200W MiniGRW1A0V100R006
CVE-2022-37070

9.8CRITICAL

Key Information:

Vendor
H3c
Vendor
CVE Published:
25 August 2022

Summary

The H3C GR-1200W MiniGRW1A0V100R006 router is susceptible to a command injection vulnerability due to improper validation of input parameters. Attackers can exploit this flaw through the 'param' parameter at DelL2tpLNSList, potentially allowing unauthorized execution of arbitrary commands. This vulnerability poses significant risks to network security, making it imperative for users to apply recommended security patches to mitigate risks associated with unauthorized access and control.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.