Security Advisory

CVE-2022-34850

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2022-10-25 16:34:00
Last updated 2025-04-15 18:45:11
Assigner talos
CVSS score 9.1
State PUBLISHED

Description

An OS command injection vulnerability exists in the web_server /action/import_authorized_keys/ functionality of Robustel R1510 3.1.16 and 3.3.0. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger this vulnerability.