CVE-2022-25621

CRITICAL

NEC UNIVERGE WA Series Firmware < 8.2.11 - Remote OS Command Injection

Title source: llm
STIX 2.1

Description

UUNIVERGE WA 1020 Ver8.2.11 and prior, UNIVERGE WA 1510 Ver8.2.11 and prior, UNIVERGE WA 1511 Ver8.2.11 and prior, UNIVERGE WA 1512 Ver8.2.11 and prior, UNIVERGE WA 2020 Ver8.2.11 and prior, UNIVERGE WA 2021 Ver8.2.11 and prior, UNIVERGE WA 2610-AP Ver8.2.11 and prior, UNIVERGE WA 2611-AP Ver8.2.11 and prior, UNIVERGE WA 2611E-AP Ver8.2.11 and prior, UNIVERGE WA WA2612-AP Ver8.2.11 and prior allows a remote attacker to execute arbitrary OS commands.

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.0139
EPSS Percentile 68.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (10)
nec/univerge_wa1020_firmware < 8.2.11
nec/univerge_wa1510_firmware < 8.2.11
nec/univerge_wa1511_firmware < 8.2.11
nec/univerge_wa1512_firmware < 8.2.11
nec/univerge_wa2020_firmware < 8.2.11
nec/univerge_wa2021_firmware < 8.2.11
nec/univerge_wa2610-ap_firmware < 8.2.11
nec/univerge_wa2611-ap_firmware < 8.2.11
nec/univerge_wa2611e-ap_firmware < 8.2.11
nec/univerge_wa2612-ap_firmware < 8.2.11
Published Mar 11, 2022
Tracked Since Feb 18, 2026