CVE-2022-42491: Siretta Quartz-Gold Firmware

Critical severity, CVSS 9.8. EPSS: 3.2% chance of exploitation in the next 30 days.

Several OS command injection vulnerabilities exist in the m2m binary of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a network request to trigger these vulnerabilities.This command injection is reachable through the m2m's M2M_CONFIG_SET command

Affected products

  • Siretta Quartz-Gold Firmware: version g5.0.1.5-210720-141020 only

Published 2023-01-26. Last modified 2026-06-17.