Vulnerability CVE-2022-22986


Published: 2022-03-31

Description:
Netcommunity OG410X and OG810X series (Netcommunity OG410Xa, OG410Xi, OG810Xa, and OG810Xi firmware Ver.2.28 and earlier) allow an attacker on the adjacent network to execute an arbitrary OS command via a specially crafted config file.

Type:

CWE-78

(Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') )

CVSS2 => (AV:A/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
8.3/10
10/10
6.5/10
Exploit range
Attack complexity
Authentication
Adjacent network
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete

 References:
https://jvn.jp/en/vu/JVNVU94900322/index.html
https://www.ntt-west.co.jp/smb/kiki_info/info/220322.html
https://business.ntt-east.co.jp/topics/2022/03_22.html

Copyright 2026, cxsecurity.com

 

Back to Top