CVE-2022-34869: Allied-Telesis Centrecom AR260S Firmware

High severity, CVSS 8.8. EPSS: 1.1% chance of exploitation in the next 30 days.

Undocumented hidden command that can be executed from the telnet function of CentreCOM AR260S V2 firmware versions prior to Ver.3.3.7 allows a remote authenticated attacker to execute an arbitrary OS command.

Affected products

  • Allied-Telesis Centrecom AR260S Firmware: before 3.3.7 (fixed in 3.3.7)

Published 2022-09-08. Last modified 2026-06-17.