CVE-2022-36553
critical · 9.8A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
Hytec Inter HWL-2511-SS v1.05 and below was discovered to contain a command injection vulnerability via the component /www/cgi-bin/popen.cgi.
9.8
CVSS
90.9%
EPSS (exploit prob.)
100th
EPSS percentile
2022-08-29
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-77
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| hytec | hwl-2511-ss_firmware | <= 1.05 |
| hytec | hwl-2511-ss | all versions |
Check a specific version with /api/v1/cve/match.
References
- https://gist.github.com/Nwqda/b27418ab801eb0b9cdbe8d042cb0249b
- https://hytec.co.jp/eng/products/our-brand/hwl-2511-ss.html
- https://hytec.co.jp/eng/wordpress/wp-content/uploads/2019/09/hwl-2511-ss-ds.3.0.pdf
- https://gist.github.com/Nwqda/b27418ab801eb0b9cdbe8d042cb0249b
- https://hytec.co.jp/eng/products/our-brand/hwl-2511-ss.html
- https://hytec.co.jp/eng/wordpress/wp-content/uploads/2019/09/hwl-2511-ss-ds.3.0.pdf
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2022-36553