CVE-2022-35733
Severity CVSS v4.0:
Pending analysis
Type:
CWE-306
Missing Authentication for Critical Function
Publication date:
23/08/2022
Last modified:
26/08/2022
Description
Missing authentication for critical function vulnerability in UNIMO Technology digital video recorders (UDR-JA1004/JA1008/JA1016 firmware versions v1.0.20.13 and earlier, and UDR-JA1016 firmware versions v2.0.20.13 and earlier) allows a remote unauthenticated attacker to execute an arbitrary OS command by sending a specially crafted request to the affected device web interface.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:unimo:udr-ja1004_firmware:*:*:*:*:*:*:*:* | 1.0.20.13 (including) | |
| cpe:2.3:h:unimo:udr-ja1004:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:unimo:udr-ja1008_firmware:*:*:*:*:*:*:*:* | 1.0.20.13 (including) | |
| cpe:2.3:h:unimo:udr-ja1008:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:unimo:udr-ja1016_firmware:*:*:*:*:*:*:*:* | 2.0.20.13 (including) | |
| cpe:2.3:h:unimo:udr-ja1016:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



