CVE-2022-44149

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
06/01/2023
Last modified:
09/04/2025

Description

The web service on Nexxt Amp300 ARN02304U8 42.103.1.5095 and 80.103.2.5045 devices allows remote OS command execution by placing &telnetd in the JSON host field to the ping feature of the goform/sysTools component. Authentication is required

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:nexxtsolutions:amp300_firmware:42.103.1.5095:*:*:*:*:*:*:*
cpe:2.3:o:nexxtsolutions:amp300_firmware:80.103.2.5045:*:*:*:*:*:*:*
cpe:2.3:h:nexxtsolutions:amp300:-:*:*:*:*:*:*:*