CVE-2022-29558: Command Injection
Published Jul 28, 2022
·Updated
Realtek rtl819x-SDK before v3.6.1 allows command injection over the web interface.
Affected Software
1 affected component
Realtek Rtl819x Software Development Kit<3.6.1
Event History
Jul 28, 2022
CVE Published
via MITRE·09:20 PM
Data Sourced
via MITRE·09:20 PM
Description
Frequently Asked Questions
1
What is CVE-2022-29558?
CVE-2022-29558 is a vulnerability that allows command injection over the web interface in Realtek rtl819x-SDK before v3.6.1.
2
How severe is CVE-2022-29558?
CVE-2022-29558 has a severity rating of 8.8 (high).
3
Which software is affected by CVE-2022-29558?
The Realtek Rtl819x Software Development Kit (SDK) before v3.6.1 is affected by CVE-2022-29558.
4
How can CVE-2022-29558 be exploited?
CVE-2022-29558 can be exploited by injecting malicious commands through the web interface of Realtek rtl819x-SDK before v3.6.1.
5
Is there a fix for CVE-2022-29558?
There is no specific fix mentioned in the provided references. It is recommended to follow the guidance provided by Realtek to mitigate the vulnerability.