CVE-2022-36557
Description
Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain an arbitrary file upload vulnerability via the restore backup function. This vulnerability allows attackers to execute arbitrary code via a crafted html file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Seiko SkyBridge MB-A100/A110 routers before 4.2.1 allow unauthenticated arbitrary file upload via the restore backup function, leading to remote code execution.
Vulnerability
The Seiko SkyBridge MB-A100 and MB-A110 LTE/3G wireless routers, firmware version 4.2.0 and below, contain an arbitrary file upload vulnerability in the restore backup function. An attacker can upload a crafted HTML file, which the device will then execute, allowing arbitrary code execution. The issue is present in all firmware versions up to and including 4.2.0 [1].
Exploitation
To exploit this vulnerability, an attacker does not require authentication or prior access; they only need network connectivity to the device's management interface. The attacker crafts an HTML file containing malicious code (e.g., PHP or other server-side script) and uploads it via the restore backup functionality. The device processes the uploaded file without proper validation or sanitization, enabling the attacker to achieve code execution [1].
Impact
Successful exploitation allows the attacker to execute arbitrary code on the device with the privileges of the web server (typically root). This leads to full compromise of the router, including the ability to intercept or redirect network traffic, access connected devices, and establish persistent backdoor access. The impact is severe as these devices are often used for IoT/M2M communications [1].
Mitigation
Seiko Solutions has released firmware version 4.2.1 to address the vulnerability. Users should update their devices to this version or later immediately. No workaround is available if the device cannot be updated, and the device should be isolated from untrusted networks until a patch is applied [1].
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Seiko/SkyBridge MB-A100/A110description
- Range: <=4.2.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- gist.github.com/Nwqda/88232102fed50b54c43871e88e993b54mitrex_refsource_MISC
- www.seiko-sol.co.jp/products/skybridge/lineup/mb-a100/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.