CVE-2022-40005: OS Command Injection
Published Dec 25, 2022
·Updated
Intelbras WiFiber 120AC inMesh before 1-1-220826 allows command injection by authenticated users, as demonstrated by the /boaform/formPing6 and /boaform/formTracert URIs for ping and traceroute.
Affected Software
4 affected components
Intelbras Wifiber 120ac Inmesh Firmware>=1.1-220216<1.1-220826
Intelbras WiFiber 120AC inMesh
All of the following
Intelbras Wifiber 120ac Inmesh Firmware>=1.1-220216<1.1-220826
Intelbras WiFiber 120AC inMesh
Remediation
Patch Available
Event History
Dec 25, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-40005?
CVE-2022-40005 is a vulnerability in Intelbras WiFiber 120AC inMesh firmware that allows command injection by authenticated users.
2
How severe is CVE-2022-40005?
CVE-2022-40005 has a severity score of 8.8, which is considered high.
3
How does CVE-2022-40005 affect Intelbras WiFiber 120AC inMesh?
CVE-2022-40005 affects Intelbras WiFiber 120AC inMesh firmware versions prior to 1-1-220826.
4
How can authenticated users exploit CVE-2022-40005?
Authenticated users can exploit CVE-2022-40005 by performing command injection through the /boaform/formPing6 and /boaform/formTracert URIs for ping and traceroute.
5
Are there any fixes or patches available for CVE-2022-40005?
Currently, there are no known fixes or patches available for CVE-2022-40005.