CVE-2022-23332
Severity CVSS v4.0:
Pending analysis
Type:
CWE-94
Code Injection
Publication date:
09/05/2022
Last modified:
08/08/2023
Description
Command injection vulnerability in Manual Ping Form (Web UI) in Shenzhen Ejoin Information Technology Co., Ltd. ACOM508/ACOM516/ACOM532 609-915-041-100-020 allows a remote attacker to inject arbitrary code via the field.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Base Score 2.0
9.00
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:ejointech:acom508_firmware:*:*:*:*:*:*:*:* | 508-609-900-241-100-020 (including) | |
| cpe:2.3:h:ejointech:acom508:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:ejointech:acom532_firmware:*:*:*:*:*:*:*:* | 532-609-915-041-100-020 (including) | |
| cpe:2.3:h:ejointech:acom532:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:ejointech:acom516_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:ejointech:acom516:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



