github.com
https://github.com/litespeedtech/openlitespeed/blob/v1.7.16.1/dist/admin/html.open/lib/CValidation.php CVE-2022-0073
HIGHRansomware
Authenticated Remote Code Execution in OpenLiteSpeed Web Server
Record summary
CVE-2022-0073 has a selected CVSS score of 8.8 (high). VulnCheck reports CVE-2022-0073 use in known ransomware campaigns.
Description
Improper Input Validation vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server dashboards allows Command Injection. This affects 1.7.0 versions before 1.7.16.1.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Mar 19, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
- Ransomware use
- Observed · VulnCheck
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated May 5, 2025 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
LiteSpeed Web ServerBrowse LiteSpeed Technologies / LiteSpeed Web ServerDefault status: unaffected | CVE List | 1.7.0 to < 1.7.16.1 | affected |
OpenLiteSpeed Web ServerBrowse LiteSpeed Technologies / OpenLiteSpeed Web ServerDefault status: unaffected | CVE List | 1.7.0 to < 1.7.16.1 | affected |
openlitespeedBrowse LiteSpeed Technologies / openlitespeed | VulnCheck | Version data not supplied | |
References
3github.com
https://github.com/litespeedtech/openlitespeed/blob/v1.7.16/dist/admin/html.open/lib/CValidation.php nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-0073