VYPR
Unrated severityNVD Advisory· Published Aug 29, 2022· Updated Aug 3, 2024

CVE-2022-36556

CVE-2022-36556

Description

Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain a command injection vulnerability via the ipAddress parameter at 07system08execute_ping_01.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Command injection vulnerability in Seiko SkyBridge MB-A100/A110 allows unauthenticated attackers to execute arbitrary commands via the ipAddress parameter of the ping functionality.

Vulnerability

The Seiko SkyBridge MB-A100 and MB-A110 routers running firmware version 4.2.0 and below contain a command injection vulnerability in the 07system08execute_ping_01 endpoint. The ipAddress parameter is not sanitized, allowing injection of arbitrary system commands. This affects all firmware versions up to and including 4.2.0 [1].

Exploitation

An attacker can exploit this vulnerability by sending a crafted HTTP request to the vulnerable endpoint with malicious input in the ipAddress parameter. No authentication is required, as the vulnerable endpoint is accessible without login. The attacker must have network access to the device's management interface.

Impact

Successful exploitation allows an unauthenticated attacker to execute arbitrary commands on the underlying operating system with root privileges, leading to full compromise of the device. This can result in information disclosure, denial of service, or use of the device as a pivot point in further attacks.

Mitigation

As of the publication date, no official patch has been released by Seiko Solutions. Users are advised to restrict network access to the management interface and monitor for any security updates from the vendor. No workaround is documented in available references [1].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.