CVE-2022-29337: OS Command Injection
C-DATA FD702XW-X-R430 v2.1.13X001 was discovered to contain a command injection vulnerability via the vacmd parameter in formlanipv6. This vulnerability allows attackers to execute arbitrary commands via a crafted HTTP request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-29337?
CVE-2022-29337 has a high severity due to its potential for remote command execution.
How do I fix CVE-2022-29337?
To fix CVE-2022-29337, update the firmware of the C-DATA FD702XW-X-R430 device to the latest version provided by the vendor.
What types of attacks can exploit CVE-2022-29337?
CVE-2022-29337 can be exploited by attackers sending specially crafted HTTP requests that include malicious command injections.
Which devices are affected by CVE-2022-29337?
CVE-2022-29337 specifically affects the C-DATA FD702XW-X-R430 firmware version 2.1.13_X001.
Is this vulnerability remotely exploitable in CVE-2022-29337?
Yes, CVE-2022-29337 is remotely exploitable, allowing attackers to execute commands without physical access to the device.