CVE-2022-42786: Wiesemann & Theis: XSS vulnerability in web interface of the Com-Server family

Published Nov 10, 2022
·
Updated

Multiple W&T Products of the ComServer Series are prone to an XSS attack. An authenticated remote Attacker can execute arbitrary web scripts or HTML via a crafted payload injected into the title of the configuration webpage

Affected Software

68 affected components
Wut At-modem-emulator Firmware<1.48
Wut At-modem-emulator
Wut Com-server \+\+ Firmware<1.48
Wut Com-server \+\+
Wut Com-server 20ma Firmware<1.48
Wut Com-server 20ma
Wut Com-server Highspeed 100basefx Firmware<1.76
Wut Com-server Highspeed 100basefx
Wut Com-server Highspeed 100baselx Firmware<1.76
Wut Com-server Highspeed 100baselx
Wut Com-server Highspeed 19\" 1port Firmware<1.76
Wut Com-server Highspeed 19\" 1port
Wut Com-server Highspeed 19\" 4port Firmware<1.76
Wut Com-server Highspeed 19\" 4port
Wut Com-server Highspeed Compact Firmware<1.76
Wut Com-server Highspeed Compact
Wut Com-server Highspeed Industry Firmware<1.76
Wut Com-server Highspeed Industry
Wut Com-server Highspeed Isolated Firmware<1.76
Wut Com-server Highspeed Isolated
Wut Com-server Highspeed Oem Firmware<1.76
Wut Com-server Highspeed Oem
Wut Com-server Highspeed Office 1port Firmware<1.76
Wut Com-server Highspeed Office 1port
Wut Com-server Highspeed Office 4port Firmware<1.76
Wut Com-server Highspeed Office 4port
Wut Com-server Highspeed Poe Firmware<1.76
Wut Com-server Highspeed Poe
Wut Com-server Highspeed Lc Firmware<1.48
Wut Com-server Highspeed Lc
Wut Com-server Highspeed Ul Firmware<1.48
Wut Com-server Highspeed Ul
Wut Com-server Highspeed Poe 3x Isolated Firmware<1.48
Wut Com-server Highspeed Poe 3x Isolated
All of the following
Wut At-modem-emulator Firmware<1.48
Wut At-modem-emulator
All of the following
Wut Com-server \+\+ Firmware<1.48
Wut Com-server \+\+
All of the following
Wut Com-server 20ma Firmware<1.48
Wut Com-server 20ma
All of the following
Wut Com-server Highspeed 100basefx Firmware<1.76
Wut Com-server Highspeed 100basefx
All of the following
Wut Com-server Highspeed 100baselx Firmware<1.76
Wut Com-server Highspeed 100baselx
All of the following
Wut Com-server Highspeed 19\" 1port Firmware<1.76
Wut Com-server Highspeed 19\" 1port
All of the following
Wut Com-server Highspeed 19\" 4port Firmware<1.76
Wut Com-server Highspeed 19\" 4port
All of the following
Wut Com-server Highspeed Compact Firmware<1.76
Wut Com-server Highspeed Compact
All of the following
Wut Com-server Highspeed Industry Firmware<1.76
Wut Com-server Highspeed Industry
All of the following
Wut Com-server Highspeed Isolated Firmware<1.76
Wut Com-server Highspeed Isolated
All of the following
Wut Com-server Highspeed Oem Firmware<1.76
Wut Com-server Highspeed Oem
All of the following
Wut Com-server Highspeed Office 1port Firmware<1.76
Wut Com-server Highspeed Office 1port
All of the following
Wut Com-server Highspeed Office 4port Firmware<1.76
Wut Com-server Highspeed Office 4port
All of the following
Wut Com-server Highspeed Poe Firmware<1.76
Wut Com-server Highspeed Poe
All of the following
Wut Com-server Highspeed Lc Firmware<1.48
Wut Com-server Highspeed Lc
All of the following
Wut Com-server Highspeed Ul Firmware<1.48
Wut Com-server Highspeed Ul
All of the following
Wut Com-server Highspeed Poe 3x Isolated Firmware<1.48
Wut Com-server Highspeed Poe 3x Isolated

Event History

Nov 10, 2022
CVE Published
via MITRE·11:02 AM
Data Sourced
via MITRE·11:02 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the vulnerability ID of this vulnerability?

The vulnerability ID is CVE-2022-42786.

2

What is the severity of CVE-2022-42786?

The severity of CVE-2022-42786 is medium with a CVSS score of 5.4

3

Which products are affected by CVE-2022-42786?

This vulnerability affects multiple W&T Products of the ComServer Series including At-modem-emulator Firmware and Com-server ++ Firmware.

4

How can an authenticated remote attacker exploit CVE-2022-42786?

An authenticated remote attacker can execute arbitrary web scripts or HTML by injecting a crafted payload into the title of the configuration webpage.

5

Is there a fix available for CVE-2022-42786?

Please refer to the vendor's website or contact the vendor for information on available fixes or patches.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203