CVE-2026-22317

A command injection vulnerability in the device’s Root CA certificate transfer workflow allows a high-privileged attacker to send crafted HTTP POST requests that result in arbitrary command execution on the underlying Linux OS with root privileges.
Configurations

No configuration.

History

17 Jun 2026, 10:19

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de inyección de comandos en el flujo de trabajo de transferencia de certificados de CA raíz del dispositivo permite a un atacante con altos privilegios enviar solicitudes HTTP POST manipuladas que resultan en la ejecución arbitraria de comandos en el sistema operativo Linux subyacente con privilegios de root.

18 Mar 2026, 08:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-18 08:16

Updated : 2026-06-17 10:19


NVD link : CVE-2026-22317

Mitre link : CVE-2026-22317

CVE.ORG link : CVE-2026-22317


JSON object : View

Products Affected

No product.

CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')