VYPR
Unrated severityNVD Advisory· Published Jan 26, 2023· Updated Nov 4, 2025

CVE-2022-42490

CVE-2022-42490

Description

Several OS command injection vulnerabilities exist in the m2m binary of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a network request to trigger these vulnerabilities.This command injection is reachable through the m2m's DOWNLOAD_CFG_FILE command

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

OS command injection in Siretta QUARTZ-GOLD's m2m service allows remote unauthenticated attackers to execute arbitrary commands via the DOWNLOAD_CFG_FILE command.

Vulnerability

The Siretta QUARTZ-GOLD industrial router (firmware version G5.0.1.5-210720-141020) contains an OS command injection vulnerability in the m2m binary. The vulnerability exists within the m2m_parse_router_config function, which constructs an nvram set command using sprintf and executes it via system(). User-supplied data from a network request is incorporated into the command without sanitization, allowing arbitrary command execution. The DOWNLOAD_CFG_FILE command is one of the commands that triggers this vulnerable code path [1].

Exploitation

An attacker can exploit this vulnerability by sending a specially crafted UDP packet to the m2m service running on the device. No authentication is required. The packet must conform to the specific format expected by the service. The attacker embeds malicious commands within the parameters of the DOWNLOAD_CFG_FILE command. When the service processes the packet, the injected commands are passed to the system() call, resulting in execution [1].

Impact

Successful exploitation allows an unauthenticated remote attacker to execute arbitrary operating system commands with root privileges. This can lead to full compromise of the device, including data exfiltration, installation of malware, or further network attacks [1].

Mitigation

As of the publication date, no fix or workaround has been disclosed in the available references. The affected version is Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. Users should monitor vendor updates and restrict network access to the m2m service until a patch is released [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Range: = G5.0.1.5-210720-141020
  • Siretta/QUARTZ-GOLDv5
    Range: G5.0.1.5-210720-141020

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.