CVE-2022-30562
MEDIUMDahua IPC-HDBW2431E-S-S2 Firmware < 2022-04 - Open Redirect via Host Header Injection
Title source: llmDescription
If the user enables the https function on the device, an attacker can modify the user’s request data packet through a man-in-the-middle attack ,Injection of a malicious URL in the Host: header of the HTTP Request results in a 302 redirect to an attacker-controlled page.
References (1)
Core 1
Core References
Vendor Advisory x_refsource_misc
https://www.dahuasecurity.com/support/cybersecurity/details/1017
Scores
CVSS v3
4.7
EPSS
0.0060
EPSS Percentile
43.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-601
Status
published
Products (40)
dahuasecurity/asi7213x-t1_firmware
< 2021-09
dahuasecurity/asi7213x_firmware
< 2021-09
dahuasecurity/asi7223x-a-t1_firmware
< 2021-09
dahuasecurity/asi7223x-a_firmware
< 2021-09
dahuasecurity/ipc-hdbw2230e-s-s2_firmware
< 2022-04
dahuasecurity/ipc-hdbw2231e-s-s2_firmware
< 2022-04
dahuasecurity/ipc-hdbw2231f-as-s2_firmware
< 2022-04
dahuasecurity/ipc-hdbw2231r-zas-s2_firmware
< 2022-04
dahuasecurity/ipc-hdbw2231r-zs-s2_firmware
< 2022-04
dahuasecurity/ipc-hdbw2431e-s-s2_firmware
< 2022-04
... and 30 more
Published
Jun 28, 2022
Tracked Since
Feb 18, 2026