CVE-2022-0365

CRITICAL

Riconmobile S9922L/S9922XL Firmware - OS Command Injection

Title source: llm
STIX 2.1

Description

The affected product is vulnerable to an authenticated OS command injection, which may allow an attacker to inject and execute arbitrary shell commands as the Admin (root) user.

References (1)

Core 1
Core References
Mitigation, Third Party Advisory, US Government Resource x_refsource_confirm
https://www.cisa.gov/uscert/ics/advisories/icsa-22-032-01

Scores

CVSS v3 9.1
EPSS 0.0218
EPSS Percentile 80.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-78
Status published
Products (2)
riconmobile/s9922l_firmware 16.10.3
riconmobile/s9922xl_firmware 16.10.3
Published Feb 04, 2022
Tracked Since Feb 18, 2026