Back

CRITICAL

ETIC Telecom Remote Access Server Insufficient Verification of Data Authenticity

Published Nov 10, 2022

Description

All versions of ETIC Telecom Remote Access Server (RAS) 4.5.0 and prior’s web portal is vulnerable to accepting malicious firmware packages that could provide a backdoor to an attacker and provide privilege escalation to the device.

Affected products

Remediation

Vendor solution

ETIC Telecom recommends updating the firmware of the affected devices to the following versions:

* ETIC Telecom RAS: version 4.7.0 or later https://www.etictelecom.com/en/softwares-download/

For the installed devices, ETIC Telecom recommends:

* For all firmware versions 4.7.0 and above, there is a code signature verification for firmware packages. For versions prior to 4.7.0, to reduce the attack surface, we advise the user to verify: (1) That the downloaded firmware comes from a trusted source (ETIC Telecom web site), and (2) The hash of the firmware files.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner icscert
Published Nov 10, 2022
Updated Apr 16, 2025
Reserved Oct 26, 2022
CISA Vulnrichment
Updated Apr 16, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner icscert
Published Nov 10, 2022
Updated Apr 16, 2025
Exploited since n/a
EUVD-2022-43061