CVE-2022-47848 is a high-severity information disclosure vulnerability (CVSS 7.5) affecting Bezeq Vtech NB403-IL and IAD604-IL routers, allowing remote attackers to gain sensitive information through the UPnP service's rootDesc.xml page. This vulnerability requires no authentication or user interaction and has a low attack complexity, posing a significant risk of data exposure. While no public exploit code or active exploitation has been observed, and community discussion is minimal, the potential for unauthorized information access remains.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
bz_2.02.07.09.13.01CPE matchmatch criteria | cpe:2.3:o:bezeq:vtech_nb403-il_firmware:bz_2.02.07.09.13.01:*:*:*:*:*:*:* | ||
bz_2.02.07.09.09tCPE matchmatch criteria | cpe:2.3:o:bezeq:vtech_iad604-il_firmware:bz_2.02.07.09.09t:*:*:*:*:*:*:* | ||
bz_2.02.07.09.13.01CPE matchmatch criteria | cpe:2.3:o:bezeq:vtech_iad604-il_firmware:bz_2.02.07.09.13.01:*:*:*:*:*:*:* | ||
bz_2.02.07.09.13tCPE matchmatch criteria | cpe:2.3:o:bezeq:vtech_iad604-il_firmware:bz_2.02.07.09.13t:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.