Back

HIGH

Cradlepoint IBR600 Command Injection

Published Nov 29, 2022

Description

Cradlepoint IBR600 NCOS versions 6.5.0.160bc2e and prior are vulnerable to shell escape, which enables local attackers with non-superuser credentials to gain full, unrestrictive shell access which may allow an attacker to execute arbitrary code.

Affected products

Remediation

Vendor solution

Cradlepoint recommends users to update to at least version:

* NCOS v7.22.70

NCOS release 7.1.0 and greater are no longer available for manual or offline download and are performed via the NetCloud Manager, which requires a subscription. For more information and NCOS upgrade best practices visit Cradlepoint Netcloud Service https://cradlepoint.com/products/netcloud-service/ .

For more information about the latest update, see the Cradlepoint Release Notes https://d2c9o94y5j661e.cloudfront.net/FW-ReleaseNotesNCOS7.22.70-050722.pdf .

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner icscert
Published Nov 29, 2022
Updated Apr 16, 2025
Reserved Sep 1, 2022
CISA Vulnrichment
Updated Apr 16, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner icscert
Published Nov 29, 2022
Updated Apr 16, 2025
Exploited since n/a
EUVD-2022-42515