CVE-2022-26780 - CVE House
Back to Database
Status published Critical CVE-2022-26780

Multiple improper input validation vulnerabilities exists in the libnvram.so nvram_import...

Vulnerability Description

Multiple improper input validation vulnerabilities exists in the libnvram.so nvram_import functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted file can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.An improper input validation vulnerability exists in the `httpd`'s `user_define_init` function. Controlling the `user_define_timeout` nvram variable can lead to remote code execution.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-26780

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

InHand Networks

View all reports →

Affected Software

InRouter302
Vulnerable Versions:
V3.5.4

Timeline

Official Publish: May 12th, 2022
Last Modified: April 15th, 2025
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Weaknesses (CWE)