Skip to main content
HIGH

CVE-2022-27226

CVSS v3

8.8

HIGH

EPSS Score

33.7 %

exploit probability, as of 2026-10-05

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

A CSRF issue in /api/crontab on iRZ Mobile Routers through 2022-03-16 allows a threat actor to create a crontab entry in the router administration panel. The cronjob will consequently execute the entry on the threat actor's defined interval, leading to remote code execution, allowing the threat actor to gain filesystem access. In addition, if the router's default credentials aren't rotated or a threat actor discovers valid credentials, remote code execution can be achieved without user interaction.

Technical details

Published
2022-03-19
Exploit-DB
EDB-50832

Frequently asked questions

What is CVE-2022-27226?

A CSRF issue in /api/crontab on iRZ Mobile Routers through 2022-03-16 allows a threat actor to create a crontab entry in the router administration panel. The cronjob will consequently execute the entry on the threat actor's defined interval, leading to remote code execution, allowing the threat actor to gain filesystem access. In addition, if the router's default credentials aren't rotated or a threat actor discovers valid credentials, remote code execution can be achieved without user interaction.

Is CVE-2022-27226 actively exploited?

Active exploitation of CVE-2022-27226 has not been confirmed. Its EPSS score was 33.7% on 2026-10-05, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2022-27226?

CVE-2022-27226 has a CVSS v3 base score of 8.8 (HIGH severity).

Is CVE-2022-27226 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 50 free checks/month · Free API key