CVE-2022-36779

PROSCEND - PROSCEND / ADVICE .Ltd - G/5G Industrial Cellular Router (with GPS)4 Unauthenticated OS Command Injection Proscend M330-w / M33-W5 / M350-5G / M350-W5G / M350-6 / M350-W6 / M301-G / M301-GW ADVICE ICR 111WG / https://www.proscend.com/en/category/industrial-Cellular-Router/industrial-Cellular-Router.html https://cdn.shopify.com/s/files/1/0036/9413/3297/files/ADVICE_Industrial_4G_LTE_Cellular_Router_ICR111WG.pdf?v=1620814301
References
Link Resource
https://www.gov.il/en/departments/faq/cve_advisories Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:proscend:m330-w_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:proscend:m330-w:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:proscend:m330-w5_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:proscend:m330-w5:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:proscend:m350-5g_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:proscend:m350-5g:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:proscend:m350-w5g_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:proscend:m350-w5g:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:proscend:m350-6_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:proscend:m350-6:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:proscend:m350-w6_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:proscend:m350-w6:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:proscend:m301-g_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:proscend:m301-g:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:proscend:m301-gw_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:proscend:m301-gw:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:advice:icr_111wg_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:advice:icr_111wg:-:*:*:*:*:*:*:*

History

16 Sep 2022, 02:32

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CPE cpe:2.3:h:proscend:m301-g:-:*:*:*:*:*:*:*
cpe:2.3:o:proscend:m350-w5g_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:proscend:m330-w:-:*:*:*:*:*:*:*
cpe:2.3:h:proscend:m330-w5:-:*:*:*:*:*:*:*
cpe:2.3:h:proscend:m350-w6:-:*:*:*:*:*:*:*
cpe:2.3:h:proscend:m301-gw:-:*:*:*:*:*:*:*
cpe:2.3:o:proscend:m350-5g_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:proscend:m330-w5_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:advice:icr_111wg:-:*:*:*:*:*:*:*
cpe:2.3:o:proscend:m350-6_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:proscend:m350-6:-:*:*:*:*:*:*:*
cpe:2.3:o:proscend:m301-g_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:advice:icr_111wg_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:proscend:m330-w_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:proscend:m301-gw_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:proscend:m350-5g:-:*:*:*:*:*:*:*
cpe:2.3:h:proscend:m350-w5g:-:*:*:*:*:*:*:*
cpe:2.3:o:proscend:m350-w6_firmware:*:*:*:*:*:*:*:*
CWE CWE-78
First Time Proscend m301-g Firmware
Proscend m330-w Firmware
Proscend m350-5g Firmware
Proscend m350-6 Firmware
Proscend m350-5g
Advice icr 111wg
Proscend
Proscend m301-g
Proscend m350-w6 Firmware
Proscend m301-gw Firmware
Proscend m350-w5g Firmware
Proscend m350-w6
Proscend m330-w
Advice
Proscend m330-w5 Firmware
Proscend m350-6
Proscend m301-gw
Proscend m350-w5g
Proscend m330-w5
Advice icr 111wg Firmware
References (MISC) https://www.gov.il/en/departments/faq/cve_advisories - (MISC) https://www.gov.il/en/departments/faq/cve_advisories - Third Party Advisory

13 Sep 2022, 15:45

Type Values Removed Values Added
New CVE

Information

Published : 2022-09-13 15:15

Updated : 2023-12-10 14:35


NVD link : CVE-2022-36779

Mitre link : CVE-2022-36779

CVE.ORG link : CVE-2022-36779


JSON object : View

Products Affected

proscend

  • m330-w_firmware
  • m350-5g
  • m330-w5
  • m350-w6_firmware
  • m301-gw
  • m350-w5g_firmware
  • m350-6
  • m330-w
  • m330-w5_firmware
  • m350-6_firmware
  • m350-w6
  • m301-g_firmware
  • m301-gw_firmware
  • m350-w5g
  • m301-g
  • m350-5g_firmware

advice

  • icr_111wg_firmware
  • icr_111wg
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')