The “puhttpsniff” service, which runs by default, is susceptible to command injection due to improperly sanitized user input. An unauthenticated attacker on the same network segment as the router can execute arbitrary commands on the device without authentication.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.tenable.com/security/research/tra-2022-37 |
|
History
Thu, 17 Apr 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: tenable
Published: 2022-12-16T00:00:00.000Z
Updated: 2025-04-17T17:31:53.707Z
Reserved: 2022-12-12T00:00:00.000Z
Link: CVE-2022-47208
Updated: 2024-08-03T14:47:29.421Z
Status : Modified
Published: 2022-12-16T20:15:08.860
Modified: 2025-04-17T18:15:45.287
Link: CVE-2022-47208
No data.