CVE-2022-22986Active Exploitation(ntt-east / og410xa)

MEDIUMCVSS 8.8 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for ntt-east og410xa systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Netcommunity OG410X and OG810X series (Netcommunity OG410Xa, OG410Xi, OG810Xa, and OG810Xi firmware Ver.2.28 and earlier) allow an attacker on the adjacent network to execute an arbitrary OS command via a specially crafted config file.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • og410xa
  • og410xa_firmware
  • og410xi
  • og410xi_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
og410xaog410xa_firmwareog410xiog410xi_firmwareog810xaog810xa_firmwareog810xiog810xi_firmware

1 version affected across 8 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-19: 1Active Exploitation · 2026-05-19: 105-19
Signal classification1 categories
Active Exploitation
1100.0%
Full discourse1 post
  • Urja@urjasec
    Active Exploitation

    CODESYS targeting. CODESYS is the underlying runtime for hundreds of PLC brands. One vulnerability in CODESYS affects every PLC built on it. PIPEDREAM exploited CVE-2022-22986 and related flaws, a single capability reaching across dozens of vendors.

    Post summary

    The post reports that the PIPEDREAM threat actor has actively exploited CVE‑2022‑22986, a flaw in CODESYS that impacts all PLCs built on the platform, demonstrating real‑world use by attackers.

    1000062
    8 followersView on X
CPE platform detail8 entries

8 of 8 entries

PartVendorProductVersionTarget SWTarget HW
HWntt-eastog410xa---
OSntt-eastog410xa_firmware---
HWntt-eastog410xi---
OSntt-eastog410xi_firmware---
HWntt-eastog810xa---
OSntt-eastog810xa_firmware---
HWntt-eastog810xi---
OSntt-eastog810xi_firmware---

Explore more