CVE-2022-28375: OS Command Injection
Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 does not property sanitize user-controlled parameters within the crtcswitchsimprofile function of the crtcrpc JSON listener. A remote attacker on the local network can inject shell metacharacters into /usr/lib/lua/5.1/luci/controller/rpc.lua to achieve remote code execution as root,
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-28375?
The severity of CVE-2022-28375 is critical with a score of 9.8.
How does CVE-2022-28375 affect Verizon 5G Home LVSKIHP OutDoorUnit firmware version 3.33.101.0?
CVE-2022-28375 affects Verizon 5G Home LVSKIHP OutDoorUnit firmware version 3.33.101.0 by allowing remote attackers on the local network to inject shell metacharacters into the crtcrpc JSON listener.
Is Verizon Lvskihp Outdoorunit firmware version 3.33.101.0 vulnerable to CVE-2022-28375?
Yes, Verizon Lvskihp Outdoorunit firmware version 3.33.101.0 is vulnerable to CVE-2022-28375.
How can an attacker exploit CVE-2022-28375?
An attacker can exploit CVE-2022-28375 by injecting shell metacharacters into /usr/lib/lua/5.1/luci/controller/rpc.lua on the local network.
What is the Common Weakness Enumeration (CWE) ID associated with CVE-2022-28375?
The CWE ID associated with CVE-2022-28375 is 78.