First published: Thu Oct 27 2022(Updated: )
A leftover debug code vulnerability exists in the httpd port 4444 upload.cgi functionality of InHand Networks InRouter302 V3.5.45. A specially-crafted HTTP request can lead to arbitrary file deletion. An attacker can send an HTTP request to trigger this vulnerability.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Inhandnetworks Ir302 Firmware | =3.5.45 | |
Inhandnetworks Ir302 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-29888 is a leftover debug code vulnerability in the httpd port 4444 upload.cgi functionality of InHand Networks InRouter302 V3.5.45.
CVE-2022-29888 can lead to arbitrary file deletion in the affected software.
CVE-2022-29888 has a severity rating of 8.1, which is considered high.
CVE-2022-29888 can be exploited by sending a specially-crafted HTTP request to the httpd port 4444 upload.cgi functionality.
Mitigate CVE-2022-29888 by updating to a secure version of the InHand Networks InRouter302 firmware if available, or apply any patches or fixes provided by the vendor.