No fixed build or workaround is published yet. Limit exposure and watch for a patch.
Steps
Written by AI from the record
Check whether your Telesquare SDT-CW3B1 is running firmware version 1.1.0.
Confirm whether the device’s network interface/web access is reachable from the internet (not just inside your office).
If it is reachable and you can’t upgrade, immediately restrict access at your firewall/router so it is not reachable from the internet.
Contact your vendor/IT support and ask for the fixed firmware for CVE-2021-46422; deploy it as soon as it is provided (no patch is currently documented in the findings).
Monitor for signs of botnet activity (suspicious outbound connections, unexpected reboots, changes to device behavior).
Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute OS commands without any authentication.
In plain language
Written by AI from the record
If you use Telesquare SDT-CW3B1 firmware 1.1.0, a remote attacker can run system commands on your device over the network without logging in—this is a high-risk issue if your device is reachable.
CVE-2021-46422 is an OS command injection in Telesquare SDT-CW3B1 firmware 1.1.0 that enables unauthenticated remote attackers to execute arbitrary operating system commands via the device’s network-facing web interface input.
If you're affected
Full device takeover
Service disruption
Malware/botnet enrollment
Data exposure from the device
What is it
This vulnerability lets someone on the internet send special input to your device and make it run commands on its own computer. Think of it like a front door that doesn’t require a key—an attacker can tell the device to do whatever they want, including taking control. If your device is online and reachable, it’s the kind of weakness that gets devices pulled into automated attacks.
Who is affected
This matters if you operate or maintain a Telesquare SDT-CW3B1 device running firmware version 1.1.0 and it’s reachable over the network. It’s especially important for devices exposed to the public internet, because the flaw does not require any login or user interaction. This is a risk when attackers can reach the device’s network-facing web interface; if the device is not reachable from the internet, the risk is substantially reduced.
How urgent is it
This is urgent because exploitation has been reported in the wild, including use by a Mirai-derived botnet reported to target internet-facing edge devices. Your exposure is straightforward: if you have the affected firmware and the device is reachable, an attacker can attempt the intrusion without needing credentials. The findings also show no known patch information, so containment may be your primary immediate step.
What to do — in detail
Confirm exposure
Identify the exact firmware version on each affected Telesquare SDT-CW3B1.
Verify whether the device is reachable from outside your network (for example, if port forwarding, UPnP, or a public DNS name points to it).
If you have centralized logs, check for any unusual web requests to the device during the period it may have been reachable.
If exposed, act now (containment)
Block inbound access to the device from the internet at your firewall/router.
Remove port forwards and disable UPnP for the device/network segment.
If remote access is needed for business operations, route it through a controlled method (VPN) rather than direct internet exposure.
Upgrade path
Ask Telesquare/vendor support for the fixed firmware specifically for CVE-2021-46422.
The provided findings state that no fix/patch information is available, so you may need to rely on vendor-provided guidance or replacement until a fixed version is identified.
Once an update exists, upgrade and then re-check the firmware version to ensure it changed.
Temporary workaround if you can’t patch
Treat the device as exposed and keep it isolated from the internet using network controls until a fixed firmware is provided.
What to monitor after containment/changes
Unexpected outbound connections from the device.
Repeated login-less web interaction attempts.
Unexpected reboots or configuration changes.
Known timeline from findings
Exploitation is reported as active in the wild (first reported July 2026), and this CVE has been used for initial infection of publicly accessible edge devices.
Technical context
Severity is critical based on the described impact: unauthenticated remote OS command execution (CWE-78). The mechanism is command injection through network-facing web interface input that is not properly sanitized, allowing attackers to execute arbitrary system commands on the device host. Findings indicate exploitation is occurring in the wild: a Mirai-derived Evooo1Bot botnet has been reported using CVE-2021-46422 to compromise internet-facing devices since July 2026, including Telesquare SDT-CW3B1.
Patch status: the findings provide no fixed version or patch information. Exploit maturity appears high enough to be publicly available (2 known public exploits are noted) and actively used per the reported incidents. KEV is not listed, so this is not a CISA “cataloged” item in the findings, but the reported in-the-wild exploitation drives the urgency.
(EPSS was provided as a prediction, but it is not used as public decision support here because the findings state exploitation has been reported.)
This is a general assessment based on public vulnerability data. It does not account for your specific infrastructure — when in doubt, consult a security specialist.