CVE-2022-26993 is a critical command injection vulnerability affecting specific Arris SBR-AC1900P, SBR-AC3200P, and SBR-AC1200P router firmware versions. Attackers can exploit this flaw by crafting malicious requests to the pppoe function, leveraging parameters like pppoeUserName, pppoePassword, and pppoe_Service. With a CVSS score of 9.8, this vulnerability allows for unauthenticated remote code execution with high impact on confidentiality, integrity, and availability. While rated as critical and having a high FAUCET Risk Score, there is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.7-b05CPE matchmatch criteria | cpe:2.3:o:arris:sbr-ac1900p_firmware:1.0.7-b05:*:*:*:*:*:*:* | ||
1.0.7-b05CPE matchmatch criteria | cpe:2.3:o:arris:sbr-ac3200p_firmware:1.0.7-b05:*:*:*:*:*:*:* | ||
1.0.5-b05CPE matchmatch criteria | cpe:2.3:o:arris:sbr-ac1200p_firmware:1.0.5-b05:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.