CVE-2022-42785
Severity CVSS v4.0:
Pending analysis
Type:
CWE-306
Missing Authentication for Critical Function
Publication date:
15/11/2022
Last modified:
21/11/2022
Description
Multiple W&T products of the ComServer Series are prone to an authentication bypass. An unathenticated remote attacker, can log in without knowledge of the password by crafting a modified HTTP GET Request.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:wut:at-modem-emulator_firmware:*:*:*:*:*:*:*:* | 1.48 (excluding) | |
| cpe:2.3:h:wut:at-modem-emulator:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:wut:com-server_\+\+_firmware:*:*:*:*:*:*:*:* | 1.48 (excluding) | |
| cpe:2.3:h:wut:com-server_\+\+:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:wut:com-server_20ma_firmware:*:*:*:*:*:*:*:* | 1.48 (excluding) | |
| cpe:2.3:h:wut:com-server_20ma:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:wut:com-server_highspeed_100basefx_firmware:*:*:*:*:*:*:*:* | 1.76 (excluding) | |
| cpe:2.3:h:wut:com-server_highspeed_100basefx:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:wut:com-server_highspeed_100baselx_firmware:*:*:*:*:*:*:*:* | 1.76 (excluding) | |
| cpe:2.3:h:wut:com-server_highspeed_100baselx:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:wut:com-server_highspeed_19\"_1port_firmware:*:*:*:*:*:*:*:* | 1.76 (excluding) | |
| cpe:2.3:h:wut:com-server_highspeed_19\"_1port:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:wut:com-server_highspeed_19\"_4port_firmware:*:*:*:*:*:*:*:* | 1.76 (excluding) | |
| cpe:2.3:h:wut:com-server_highspeed_19\"_4port:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:wut:com-server_highspeed_compact_firmware:*:*:*:*:*:*:*:* | 1.76 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



