← Vulnerability feed

Vulnerability record · CVE-2021-46422 · published 27 April 2022

CVE-2021-46422: Telesquare SDT-CW3B1 router OS command injection

Telesquare · Sdt Cs3b1 Firmware

Telesquare SDT-CW3B1 1.1.0 contains an OS command injection flaw (CWE-78) that lets a remote attacker run arbitrary operating system commands. The vulnerability is rated critical (CVSS 3.1 9.8) and requires no authentication or user interaction, making any exposed device a direct target.

9.8 CVSS 3.1 Critical EPSS 94% · top 0.2% CWE-78 · OS command injection
9.8CVSS 3.1 base score, v2 10.0
94%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute OS commands without any authentication.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated remote OS command injection with a 9.8 CVSS score, public exploit code and a 99.8th percentile EPSS probability makes this an urgent fix.

What it is

Telesquare SDT-CW3B1 1.1.0 contains an OS command injection flaw (CWE-78) that lets a remote attacker run arbitrary operating system commands. The vulnerability is rated critical (CVSS 3.1 9.8) and requires no authentication or user interaction, making any exposed device a direct target.

Impact

An attacker gains unauthenticated remote code execution on the device, allowing full compromise of confidentiality, integrity and availability. This can be used to pivot into the network the device sits on or to enroll it in a botnet.

Attack surface

The flaw is reachable over the network (AV:N) with no privileges (PR:N) and no user interaction (UI:N), so any internet- or LAN-exposed SDT-CW3B1 1.1.0 interface is a candidate. No credentials are needed to trigger the injection.

Exploitation

CISA KEV does not list this CVE, but public exploit code is referenced (Packet Storm and a Google Drive link tagged Exploit) and EPSS is very high at 0.94342 (99.8th percentile), indicating active exploitation is likely.

What to do

  • Apply the vendor fix for SDT-CW3B1 1.1.0 or later if available; if no patch exists, replace or retire the device.
  • Remove the device from direct internet exposure and restrict management access to trusted internal networks only.
  • Place the device behind a firewall or reverse proxy that filters requests to the vulnerable endpoint.
  • Monitor vendor advisories for a patched firmware release and schedule immediate upgrade.
  • If the device cannot be patched or isolated, power it down or replace it with a supported product.

Detection

  • Inspect web server or device logs for requests containing shell metacharacters (;, |, $(), backticks) to the vulnerable endpoint.
  • Alert on unexpected outbound connections or process execution from the SDT-CW3B1 device.
  • Use network monitoring to flag anomalous traffic to and from the device's management interface.
  • Search for known exploit payload strings from the public Packet Storm references in HTTP request logs.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-46422 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-12526Telesquare sdt-cs3b1 firmware hard-coded credentials vulnerabilityTelesquare SDT-CS3B1 and SDT-CW3B1 devices through 1.2.0 have a default factory account. Remote attackers can obtain access to the device via TELNET …EPSS 2.3%9.3CVE-2017-20223Telesquare sdt-cs3b1 firmware insecure direct object reference vulnerabilityTelesquare SKT LTE Router SDT-CS3B1 firmware version 1.2.0 contains an insecure direct object reference vulnerability that allows attackers to bypass…EPSS 0.52%9.3CVE-2017-20224Telesquare sdt-cs3b1 firmware unrestricted file upload vulnerabilityTelesquare SKT LTE Router SDT-CS3B1 version 1.2.0 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload mal…EPSS 1.0%8.7CVE-2017-20222Telesquare sdt-cs3b1 firmware missing authentication for critical function vulnerabilityTelesquare SKT LTE Router SDT-CS3B1 software version 1.2.0 contains an unauthenticated remote reboot vulnerability that allows attackers to trigger d…EPSS 0.71%5.3CVE-2017-20221Telesquare sdt-cs3b1 firmware cross-site request forgery vulnerabilityTelesquare SKT LTE Router SDT-CS3B1 version 1.2.0 contains a cross-site request forgery vulnerability that allows authenticated attackers to execute …EPSS 0.29%8.8CVE-2026-53266Linux kernel ebtables SNAT out-of-bounds write in ARP rewriteThe ebtables SNAT target rewrites the ARP sender hardware address via skb_store_bits() without first making that range writable. When the ARP SHA byt…KEVEPSS 0.65%analysed8.8CVE-2026-87491Google Chrome V8 out-of-bounds write enables sandbox code executionChrome before 153.0.8010.36 contains an out-of-bounds write in the V8 JavaScript engine. A crafted HTML page can trigger the memory corruption, and b…KEVEPSS 3.1%analysed9.8CVE-2025-25249Fortinet FortiOS and FortiSwitchManager heap buffer overflow via crafted packetsA heap-based buffer overflow (CWE-122/CWE-787) in Fortinet FortiOS 6.4 through 7.6.3 and FortiSwitchManager 7.0 through 7.2.6 lets an unauthenticated…KEVEPSS 3.9%analysed

Source: NIST National Vulnerability Database (record CVE-2021-46422), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.