What is CVE-2026-38710?
CVE-2026-38710 is a command injection vulnerability in the system.setclock interface, affecting TR1200 v2.4.15 and TR3000 v2.4.21 devices. It allows attackers to execute arbitrary commands as root via crafted input. Updating the firmware and enforcing network-level access controls are recommended mitigations.
Azərbaycanca: CVE-2026-38710 cihazların `system.setclock` interfeysində command injection zəifliyidir. Bu boşluq TR1200 v2.4.15 və TR3000 v2.4.21 modellərinə təsir edir, təcavüzkara root icazı ilə ixtiyari əmrlər yeritməyə imkan verir. Cihazların proqram təminatını ən son versiyaya yeniləmək və şəbəkə səviyyəsində giriş nəzarəti tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-77
FAQ2
Which device models are affected by CVE-2026-38710?
TR1200 v2.4.15 and TR3000 v2.4.21 models.
At what privilege level can an attacker execute commands through CVE-2026-38710?
As root.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.