CVE-2022-27226 Information
Description
A CSRF issue in /api/crontab on iRZ Mobile Routers through 2022-03-16 allows a threat actor to create a crontab entry in the router administration panel. The cronjob will consequently execute the entry on the threat actor’s defined interval leading to remote code execution allowing the threat actor to gain filesystem access. In addition if the router’s default credentials aren’t rotated or a threat actor discovers valid credentials remote code execution can be achieved without user interaction.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Reference
https://en.irz.ru https://johnjhacking.com/blog/cve-2022-27226/ https://github.com/SakuraSamuraii/ez-iRZ http://packetstormsecurity.com/files/166396/iRZ-Mobile-Router-Cross-Site-Request-Forgery-Remote-Code-Execution.html
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.8
Share on: