CVE-2022-26991 is a critical command injection vulnerability affecting Arris SBR-AC1900P, SBR-AC3200P, and SBR-AC1200P routers. This flaw allows unauthenticated attackers to execute arbitrary commands by manipulating the TimeZone parameter within the NTP function. With a CVSS score of 9.8, this vulnerability presents a severe risk, enabling complete compromise of affected devices with no user interaction required. Despite its critical nature, there is currently no public exploit code available, nor is there evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.7-b05CPE matchmatch criteria | cpe:2.3:o:arris:sbr-ac1900p_firmware:1.0.7-b05:*:*:*:*:*:*:* | ||
1.0.7-b05CPE matchmatch criteria | cpe:2.3:o:arris:sbr-ac3200p_firmware:1.0.7-b05:*:*:*:*:*:*:* | ||
1.0.5-b05CPE matchmatch criteria | cpe:2.3:o:arris:sbr-ac1200p_firmware:1.0.5-b05:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.