CVE-2022-25621
CRITICALNEC UNIVERGE WA Series Firmware < 8.2.11 - Remote OS Command Injection
Title source: llmDescription
UUNIVERGE WA 1020 Ver8.2.11 and prior, UNIVERGE WA 1510 Ver8.2.11 and prior, UNIVERGE WA 1511 Ver8.2.11 and prior, UNIVERGE WA 1512 Ver8.2.11 and prior, UNIVERGE WA 2020 Ver8.2.11 and prior, UNIVERGE WA 2021 Ver8.2.11 and prior, UNIVERGE WA 2610-AP Ver8.2.11 and prior, UNIVERGE WA 2611-AP Ver8.2.11 and prior, UNIVERGE WA 2611E-AP Ver8.2.11 and prior, UNIVERGE WA WA2612-AP Ver8.2.11 and prior allows a remote attacker to execute arbitrary OS commands.
References (1)
Core 1
Core References
Vendor Advisory x_refsource_misc
https://jpn.nec.com/security-info/secinfo/nv22-004_en.html
Scores
CVSS v3
9.8
EPSS
0.0139
EPSS Percentile
68.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-78
Status
published
Products (10)
nec/univerge_wa1020_firmware
< 8.2.11
nec/univerge_wa1510_firmware
< 8.2.11
nec/univerge_wa1511_firmware
< 8.2.11
nec/univerge_wa1512_firmware
< 8.2.11
nec/univerge_wa2020_firmware
< 8.2.11
nec/univerge_wa2021_firmware
< 8.2.11
nec/univerge_wa2610-ap_firmware
< 8.2.11
nec/univerge_wa2611-ap_firmware
< 8.2.11
nec/univerge_wa2611e-ap_firmware
< 8.2.11
nec/univerge_wa2612-ap_firmware
< 8.2.11
Published
Mar 11, 2022
Tracked Since
Feb 18, 2026