Vulnerability record · CVE-2021-46422 · published 27 April 2022
CVE-2021-46422: Telesquare SDT-CW3B1 router OS command injection
Telesquare · Sdt Cs3b1 Firmware
Telesquare SDT-CW3B1 1.1.0 contains an OS command injection flaw (CWE-78) that lets a remote attacker run arbitrary operating system commands. The vulnerability is rated critical (CVSS 3.1 9.8) and requires no authentication or user interaction, making any exposed device a direct target.
Description
Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute OS commands without any authentication.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote OS command injection with a 9.8 CVSS score, public exploit code and a 99.8th percentile EPSS probability makes this an urgent fix.
What it is
Telesquare SDT-CW3B1 1.1.0 contains an OS command injection flaw (CWE-78) that lets a remote attacker run arbitrary operating system commands. The vulnerability is rated critical (CVSS 3.1 9.8) and requires no authentication or user interaction, making any exposed device a direct target.
Impact
An attacker gains unauthenticated remote code execution on the device, allowing full compromise of confidentiality, integrity and availability. This can be used to pivot into the network the device sits on or to enroll it in a botnet.
Attack surface
The flaw is reachable over the network (AV:N) with no privileges (PR:N) and no user interaction (UI:N), so any internet- or LAN-exposed SDT-CW3B1 1.1.0 interface is a candidate. No credentials are needed to trigger the injection.
Exploitation
CISA KEV does not list this CVE, but public exploit code is referenced (Packet Storm and a Google Drive link tagged Exploit) and EPSS is very high at 0.94342 (99.8th percentile), indicating active exploitation is likely.
What to do
- Apply the vendor fix for SDT-CW3B1 1.1.0 or later if available; if no patch exists, replace or retire the device.
- Remove the device from direct internet exposure and restrict management access to trusted internal networks only.
- Place the device behind a firewall or reverse proxy that filters requests to the vulnerable endpoint.
- Monitor vendor advisories for a patched firmware release and schedule immediate upgrade.
- If the device cannot be patched or isolated, power it down or replace it with a supported product.
Detection
- Inspect web server or device logs for requests containing shell metacharacters (;, |, $(), backticks) to the vulnerable endpoint.
- Alert on unexpected outbound connections or process execution from the SDT-CW3B1 device.
- Use network monitoring to flag anomalous traffic to and from the device's management interface.
- Search for known exploit payload strings from the public Packet Storm references in HTTP request logs.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/167201/SDT-CW3B1-1.1.0-Command-Injection.html | Third Party Advisory |
| http://packetstormsecurity.com/files/167387/Telesquare-SDT-CW3B1-1.1.0-Command-Injection.html | ExploitThird Party Advisory |
| https://drive.google.com/drive/folders/1YJlVlb4SlTEGONzIjiMwd2P7ucP_Pm7T?usp=sharing | ExploitThird Party Advisory |
| http://packetstormsecurity.com/files/167201/SDT-CW3B1-1.1.0-Command-Injection.html | Third Party Advisory |
| http://packetstormsecurity.com/files/167387/Telesquare-SDT-CW3B1-1.1.0-Command-Injection.html | ExploitThird Party Advisory |
| https://drive.google.com/drive/folders/1YJlVlb4SlTEGONzIjiMwd2P7ucP_Pm7T?usp=sharing | ExploitThird Party Advisory |
Track CVE-2021-46422 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-46422), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.