← All CVEs

CVE-2022-29593

medium · 5.9

relay_cgi.cgi on Dingtian DT-R002 2CH relay devices with firmware 3.1.276A allows an attacker to replay HTTP post requests without the need for authentication or a valid signed/authorized request.

5.9
CVSS
14.0%
EPSS (exploit prob.)
96th
EPSS percentile
2022-07-14
Published

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

Weaknesses

CWE-294

Affected products

VendorProductAffected versions
dingtian-techdt-r004_firmware3.1.276a
dingtian-techdt-r004all versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2022-29593