CVE-2022-27226 describes a Critical Cross-Site Request Forgery (CSRF) vulnerability in iRZ Mobile Routers, including models like RL01, RL21, RU21, and RU41. This flaw allows an unauthenticated attacker to create malicious cron jobs on the router's administration panel, leading to remote code execution and filesystem access. With a CVSS score of 8.8 (High), the vulnerability is easily exploitable over the network with low attack complexity, requiring user interaction (e.g., clicking a malicious link) to trigger. While not listed in CISA's KEV catalog, public exploit code exists (EDB-50832), and it has garnered significant community discussion and media coverage, including mentions in articles about the EnemyBot malware, indicating its potential for broader exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2022-03-16CPE matchmatch criteria | cpe:2.3:o:irz:ru21_firmware:*:*:*:*:*:*:*:* | ||
<= 2022-03-16CPE matchmatch criteria | cpe:2.3:o:irz:ru21w_firmware:*:*:*:*:*:*:*:* | ||
<= 2022-03-16CPE matchmatch criteria | cpe:2.3:o:irz:rl21_firmware:*:*:*:*:*:*:*:* | ||
<= 2022-03-16CPE matchmatch criteria | cpe:2.3:o:irz:ru41_firmware:*:*:*:*:*:*:*:* | ||
<= 2022-03-16CPE matchmatch criteria | cpe:2.3:o:irz:rl01_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.