Vulnerability record · CVE-2022-27226 · published 19 March 2022
CVE-2022-27226: Irz ru21 firmware cross-site request forgery vulnerability
Irz · Ru21 Firmware
A CSRF issue in /api/crontab on iRZ Mobile Routers through 2022-03-16 allows a threat actor to create a crontab entry in the router administration panel. The cronjob will consequently execute the entry on the threat actor's defined interval, leading to remote code execution, allowing the threat actor to gain filesystem access. In addition, if the router's default credentials aren't rotated or a threat actor discovers valid credentials, remote code execution can be achieved without user interaction.
Description
A CSRF issue in /api/crontab on iRZ Mobile Routers through 2022-03-16 allows a threat actor to create a crontab entry in the router administration panel. The cronjob will consequently execute the entry on the threat actor's defined interval, leading to remote code execution, allowing the threat actor to gain filesystem access. In addition, if the router's default credentials aren't rotated or a threat actor discovers valid credentials, remote code execution can be achieved without user interaction.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/166396/iRZ-Mobile-Router-Cross-Site-Request-Forgery-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://en.irz.ru | Product |
| https://github.com/SakuraSamuraii/ez-iRZ | ExploitThird Party Advisory |
| https://johnjhacking.com/blog/cve-2022-27226/ | ExploitThird Party Advisory |
| http://packetstormsecurity.com/files/166396/iRZ-Mobile-Router-Cross-Site-Request-Forgery-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://en.irz.ru | Product |
| https://github.com/SakuraSamuraii/ez-iRZ | ExploitThird Party Advisory |
| https://johnjhacking.com/blog/cve-2022-27226/ | ExploitThird Party Advisory |
Track CVE-2022-27226 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-27226), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.