CVE-2022-4002: Command Injection
Published Jul 31, 2024
·Updated
A command injection vulnerability could allow an authenticated user to execute operating system commands as root via a specially crafted API request.
Affected Software
2 affected components
All of the following
Motorola Q14 Firmware<1.5.0.16
Motorola Q14
Remediation
Information
Update Motorola Q14 Mesh Router firmware to v1.5.0.16 or later.
Event History
Jul 31, 2024
CVE Published
via MITRE·08:29 PM
Data Sourced
via MITRE·08:29 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-4002?
CVE-2022-4002 is classified as a high-severity command injection vulnerability.
2
How do I fix CVE-2022-4002?
To fix CVE-2022-4002, upgrade the Motorola Q14 firmware to version 1.5.0.16 or later.
3
Who is affected by CVE-2022-4002?
CVE-2022-4002 affects authenticated users of the Motorola Q14 firmware version 1.5.0.16 and earlier.
4
What can an attacker do with CVE-2022-4002?
An attacker can execute operating system commands as root through a specially crafted API request due to CVE-2022-4002.
5
Is CVE-2022-4002 exploitable remotely?
CVE-2022-4002 is potentially exploitable remotely if the attacker has authentication credentials.