# CVE-2022-3203

## Summary

- **CVE ID:** CVE-2022-3203
- **Severity:** CRITICAL
- **CVSS Score:** 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-912
- **Published:** Oct 21, 2022
- **Last Modified:** Mar 13, 2026

## Description

On ORing net IAP-420(+) with FW version 2.0m a telnet server is enabled by default and cannot permanently be disabled. You can connect to the device via LAN or WiFi with hardcoded credentials and get an administrative shell. These credentials are reset to defaults with every reboot.

## Affected Products

- ORing — IAP-420(+) (FW 2.0m)

## References

- [CNA](https://mads.uniud.it/2022/09/lord-of-the-orings/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.35%
- **EPSS Percentile:** 57.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._