CVE-2022-28374: OS Command Injection
Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 does not property sanitize user-controlled parameters within the DMACC URLs on the Settings page of the Engineering portal. An authenticated remote attacker on the local network can inject shell metacharacters into /usr/lib/lua/5.1/luci/controller/admin/settings.lua to achieve remote code execution as root.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-28374?
CVE-2022-28374 is considered a high severity vulnerability due to the potential for remote code execution.
How do I fix CVE-2022-28374?
To mitigate CVE-2022-28374, ensure that the firmware is updated to a version that properly sanitizes user input parameters.
Who is affected by CVE-2022-28374?
CVE-2022-28374 affects users of the Verizon 5G Home LVSKIHP Outdoor Unit with firmware version 3.33.101.0.
What type of attack is possible with CVE-2022-28374?
An authenticated remote attacker on the local network can exploit CVE-2022-28374 to inject shell commands.
What systems are impacted by CVE-2022-28374?
CVE-2022-28374 impacts the Verizon LVSKIHP Outdoor Unit specifically with the mentioned firmware version.