CVE-2022-41870

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
30/09/2022
Last modified:
20/05/2025

Description

AP Manager in Innovaphone before 13r2 Service Release 17 allows command injection via a modified service ID during app upload.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:innovaphone:innovaphone_firmware:*:*:*:*:*:*:*:* 13r2 (excluding)
cpe:2.3:o:innovaphone:innovaphone_firmware:13r2:-:*:*:*:*:*:*
cpe:2.3:o:innovaphone:innovaphone_firmware:13r2:service_release_12:*:*:*:*:*:*
cpe:2.3:o:innovaphone:innovaphone_firmware:13r2:service_release_13:*:*:*:*:*:*
cpe:2.3:o:innovaphone:innovaphone_firmware:13r2:service_release_14:*:*:*:*:*:*
cpe:2.3:o:innovaphone:innovaphone_firmware:13r2:service_release_15:*:*:*:*:*:*
cpe:2.3:o:innovaphone:innovaphone_firmware:13r2:service_release_16:*:*:*:*:*:*