ZeroHour

CVE-2021-22646

CVSS 3.1
9.8 critical
EPSS
1%p69
Published
()
Modified
Description

The “ipk” package containing the configuration created by TWinSoft can be uploaded, extracted, and executed in Ovarro TBox, allowing malicious code execution.

Vendors
ovarro
Products
twinsoft, tbox lt2-530 firmware, tbox lt2-532 firmware, tbox lt2-540 firmware, tbox ms-cpu32 firmware, tbox ms-cpu32-s2 firmware, tbox rm2 firmware, tbox tg2 firmware
Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news