CVE-2022-23770

HIGH

wisa smart_wing_cms < 19051 - Remote Command Execution via API Constructor Parameter

Title source: llm
STIX 2.1

Description

This vulnerability could allow a remote attacker to execute remote commands with improper validation of parameters of certain API constructors. Remote attackers could use this vulnerability to execute malicious commands such as directory traversal.

References (1)

Core 1

Scores

CVSS v3 8.8
EPSS 0.0140
EPSS Percentile 69.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-20 CWE-22
Status published
Products (1)
wisa/smart_wing_cms < 19051
Published Oct 17, 2022
Tracked Since Feb 18, 2026