OS Command Injection in Carrier products - CVE-2022-31486
Published: June 3, 2022
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation. A remote user can pass specially crafted data to the application and execute arbitrary OS commands on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
LNL-X2220
LNL-X3300
LNL-X4420
LNL-4420
S2-LP-1501
S2-LP-4502
S2-LP-2500
S2-LP-1502
How to mitigate CVE-2022-31486
LNL-X2220 - update to 1.297
LNL-X3300 - update to 1.297
LNL-X4420 - update to 1.297
LNL-4420 - update to 1.297
S2-LP-1501 - update to 1.303
S2-LP-4502 - update to 1.303
S2-LP-2500 - update to 1.303
S2-LP-1502 - update to 1.303