nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-28054 CVE-2022-28054
CRITICAL
VanDyke Software VShell for Windows Trigger Action Script Vulnerability
Record summary
CVE-2022-28054 has a selected CVSS score of 9.8 (critical).
Description
Improper sanitization of trigger action scripts in VanDyke Software VShell for Windows v4.6.2 allows attackers to execute arbitrary code via a crafted value.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Oct 20, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
vshellBrowse vandyke / vshell | VulnCheck | Version data not supplied | |
References
2vandyke.com
https://www.vandyke.com/support/advisory/2022/02/remote-execution-via-triggers.html