CVE-2022-25621
Severity CVSS v4.0:
Pending analysis
Type:
CWE-78
OS Command Injections
Publication date:
11/03/2022
Last modified:
22/03/2022
Description
UUNIVERGE WA 1020 Ver8.2.11 and prior, UNIVERGE WA 1510 Ver8.2.11 and prior, UNIVERGE WA 1511 Ver8.2.11 and prior, UNIVERGE WA 1512 Ver8.2.11 and prior, UNIVERGE WA 2020 Ver8.2.11 and prior, UNIVERGE WA 2021 Ver8.2.11 and prior, UNIVERGE WA 2610-AP Ver8.2.11 and prior, UNIVERGE WA 2611-AP Ver8.2.11 and prior, UNIVERGE WA 2611E-AP Ver8.2.11 and prior, UNIVERGE WA WA2612-AP Ver8.2.11 and prior allows a remote attacker to execute arbitrary OS commands.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:nec:univerge_wa1020_firmware:*:*:*:*:*:*:*:* | 8.2.11 (including) | |
| cpe:2.3:h:nec:univerge_wa1020:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:nec:univerge_wa1510_firmware:*:*:*:*:*:*:*:* | 8.2.11 (including) | |
| cpe:2.3:h:nec:univerge_wa1510:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:nec:univerge_wa1511_firmware:*:*:*:*:*:*:*:* | 8.2.11 (including) | |
| cpe:2.3:h:nec:univerge_wa1511:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:nec:univerge_wa1512_firmware:*:*:*:*:*:*:*:* | 8.2.11 (including) | |
| cpe:2.3:h:nec:univerge_wa1512:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:nec:univerge_wa2020_firmware:*:*:*:*:*:*:*:* | 8.2.11 (including) | |
| cpe:2.3:h:nec:univerge_wa2020:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:nec:univerge_wa2021_firmware:*:*:*:*:*:*:*:* | 8.2.11 (including) | |
| cpe:2.3:h:nec:univerge_wa2021:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:nec:univerge_wa2610-ap_firmware:*:*:*:*:*:*:*:* | 8.2.11 (including) | |
| cpe:2.3:h:nec:univerge_wa2610-ap:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:nec:univerge_wa2611-ap_firmware:*:*:*:*:*:*:*:* | 8.2.11 (including) |
To consult the complete list of CPE names with products and versions, see this page



