CVE-2022-27226
CVSS v3
8.8
HIGH
EPSS Score
33.7 %
exploit probability, as of 2026-10-05
CISA KEV
No
known exploited
Exploitation
—
SSVC status
Description
A CSRF issue in /api/crontab on iRZ Mobile Routers through 2022-03-16 allows a threat actor to create a crontab entry in the router administration panel. The cronjob will consequently execute the entry on the threat actor's defined interval, leading to remote code execution, allowing the threat actor to gain filesystem access. In addition, if the router's default credentials aren't rotated or a threat actor discovers valid credentials, remote code execution can be achieved without user interaction.
Technical details
- Published
- 2022-03-19
- Exploit-DB
- EDB-50832
Frequently asked questions
What is CVE-2022-27226?
A CSRF issue in /api/crontab on iRZ Mobile Routers through 2022-03-16 allows a threat actor to create a crontab entry in the router administration panel. The cronjob will consequently execute the entry on the threat actor's defined interval, leading to remote code execution, allowing the threat actor to gain filesystem access. In addition, if the router's default credentials aren't rotated or a threat actor discovers valid credentials, remote code execution can be achieved without user interaction.
Is CVE-2022-27226 actively exploited?
Active exploitation of CVE-2022-27226 has not been confirmed. Its EPSS score was 33.7% on 2026-10-05, the estimated probability of exploitation in the next 30 days.
What is the CVSS score for CVE-2022-27226?
CVE-2022-27226 has a CVSS v3 base score of 8.8 (HIGH severity).
Is CVE-2022-27226 affecting your environment?
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
No credit card required · 50 free checks/month · Free API key
Other 2022 vulnerabilities worth triaging
Ranked by exploit probability (EPSS).