First published: Fri Dec 23 2022(Updated: )
IP-COM M50 V15.11.0.33(10768) was discovered to contain a command injection vulnerability via the usbPartitionName parameter in the formSetUSBPartitionUmount function. This vulnerability is exploited via a crafted GET request.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ip-com M50 Firmware | =15.11.0.33 | |
IP-COM M50 | ||
All of | ||
Ip-com M50 Firmware | =15.11.0.33 | |
IP-COM M50 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-45717 is considered high due to its potential for command injection exploits.
To fix CVE-2022-45717, update the IP-COM M50 firmware to a version that does not contain this vulnerability.
CVE-2022-45717 affects the IP-COM M50 firmware version 15.11.0.33.
Yes, CVE-2022-45717 can be exploited remotely via a crafted GET request.
The impact of CVE-2022-45717 includes potential unauthorized command execution on the affected device.