Record summary

CVE-2022-28054 has a selected CVSS score of 9.8 (critical).

Description

Improper sanitization of trigger action scripts in VanDyke Software VShell for Windows v4.6.2 allows attackers to execute arbitrary code via a crafted value.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Oct 20, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

References

2