CVE-2022-23770
HIGHwisa smart_wing_cms < 19051 - Remote Command Execution via API Constructor Parameter
Title source: llmDescription
This vulnerability could allow a remote attacker to execute remote commands with improper validation of parameters of certain API constructors. Remote attackers could use this vulnerability to execute malicious commands such as directory traversal.
References (1)
Core 1
Core References
Third Party Advisory
https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66963
Scores
CVSS v3
8.8
EPSS
0.0140
EPSS Percentile
69.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-20
CWE-22
Status
published
Products (1)
wisa/smart_wing_cms
< 19051
Published
Oct 17, 2022
Tracked Since
Feb 18, 2026