VYPR
Unrated severityNVD Advisory· Published Aug 29, 2022· Updated Aug 3, 2024

CVE-2022-36559

CVE-2022-36559

Description

Seiko SkyBridge MB-A200 v01.00.04 and below was discovered to contain a command injection vulnerability via the Ping parameter at ping_exec.cgi.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Command injection in Seiko SkyBridge MB-A200 router via Ping parameter in ping_exec.cgi allows remote command execution.

Vulnerability

An authenticated command injection vulnerability exists in Seiko SkyBridge MB-A200 routers running firmware version v01.00.04 and below [1]. The flaw is located in the Ping parameter of the ping_exec.cgi web interface script. An attacker with network access to the administrative web interface can inject arbitrary system commands by crafting a malicious Ping request.

Exploitation

To exploit this vulnerability, an attacker must have valid administrative credentials for the web interface. With those credentials, the attacker sends a specially crafted HTTP POST request to ping_exec.cgi with a malicious payload in the Ping parameter. The request is processed without proper sanitization, leading to command execution on the device.

Impact

Successful exploitation allows the attacker to execute arbitrary commands on the router operating system with root privileges. This can lead to full compromise of the device, including data exfiltration, further network attacks, or disruption of services.

Mitigation

No official patch or fixed version is mentioned in the available references [1]. Users should restrict network access to the administrative interface and consider upgrading to a newer hardware revision if available. As of the publication date (August 29, 2022), the vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.