CVE-2022-40005

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
25/12/2022
Last modified:
05/01/2023

Description

Intelbras WiFiber 120AC inMesh before 1-1-220826 allows command injection by authenticated users, as demonstrated by the /boaform/formPing6 and /boaform/formTracert URIs for ping and traceroute.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:intelbras:wifiber_120ac_inmesh_firmware:*:*:*:*:*:*:*:* 1.1-220216 (including) 1.1-220826 (excluding)
cpe:2.3:h:intelbras:wifiber_120ac_inmesh:-:*:*:*:*:*:*:*