CVE-2022-22845

CRITICAL

Qxip Homer Webapp < 1.4.28 - Hard-coded Credentials

Title source: rule

Description

QXIP SIPCAPTURE homer-app before 1.4.28 for HOMER 7.x has the same 167f0db2-f83e-4baa-9736-d56064a5b415 JWT secret key across different customers' installations.

Exploits (1)

nomisec WORKING POC 2 stars
by OmriBaso · poc
https://github.com/OmriBaso/CVE-2022-22845-Exploit

Scores

CVSS v3 9.8
EPSS 0.1348
EPSS Percentile 94.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-798
Status published
Products (1)
qxip/homer_webapp < 1.4.28
Published Jan 10, 2022
Tracked Since Feb 18, 2026