CVE-2022-37661
57Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.
ssvc Actepss 34%
from disclosure to weapon58 days
Published on NVDSep 14
1st PoC+58d
VulnCheck+71d
exploitation probability
34%top 2% of all CVEs
observed exploitation
yesVulnCheck
4 public exploit(s)
SmartRG SR506n 2.5.15 and SR510n 2.6.13 routers are vulnerable to Remote Code Execution (RCE) via the ping host feature.
Affected products
n/a · n/apublic PoCs found — 4
exploitdbwww.exploit-db.com/exploits/51031unverifiedcve_referencepacketstormsecurity.com/files/168336/SmartRG-Router-2.6.13-Remote-Code-Execution.htmlunverifiedcve_referencepacketstormsecurity.com/files/169816/SmartRG-Router-SR510n-2.6.13-Remote-Code-Execution.htmlunverifiedcve_referencepacketstormsecurity.com/files/cve/CVE-2022-37661unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://packetstormsecurity.com/files/168336/SmartRG-Router-2.6.13-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/169816/SmartRG-Router-SR510n-2.6.13-Remote-Code-Execution.htmlhttps://cxsecurity.com/issue/WLB-2022090029https://packetstormsecurity.com/files/cve/CVE-2022-37661