Lucene search

K
cveMitreCVE-2022-45725
HistoryFeb 13, 2023 - 2:15 p.m.

CVE-2022-45725

2023-02-1314:15:10
CWE-20
mitre
web.nvd.nist.gov
19
cve-2022-45725
improper input validation
comfast router
cf-wr6110n
v2.3.1
remote code execution
http post request
nvd

CVSS3

8.8

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

8.8

Confidence

High

EPSS

0.004

Percentile

74.4%

Improper Input Validation in Comfast router CF-WR6110N V2.3.1 allows a remote attacker on the same network to execute arbitrary code on the target via an HTTP POST request

Affected configurations

Nvd
Node
comfastcf-wr610n_firmwareMatch2.3.1
AND
comfastcf-wr610nMatch-
VendorProductVersionCPE
comfastcf-wr610n_firmware2.3.1cpe:2.3:o:comfast:cf-wr610n_firmware:2.3.1:*:*:*:*:*:*:*
comfastcf-wr610n-cpe:2.3:h:comfast:cf-wr610n:-:*:*:*:*:*:*:*

CVSS3

8.8

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

8.8

Confidence

High

EPSS

0.004

Percentile

74.4%

Related for CVE-2022-45725