CVE-2022-30562

MEDIUM

Dahua IPC-HDBW2431E-S-S2 Firmware < 2022-04 - Open Redirect via Host Header Injection

Title source: llm
STIX 2.1

Description

If the user enables the https function on the device, an attacker can modify the user’s request data packet through a man-in-the-middle attack ,Injection of a malicious URL in the Host: header of the HTTP Request results in a 302 redirect to an attacker-controlled page.

References (1)

Core 1
Core References

Scores

CVSS v3 4.7
EPSS 0.0060
EPSS Percentile 43.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-601
Status published
Products (40)
dahuasecurity/asi7213x-t1_firmware < 2021-09
dahuasecurity/asi7213x_firmware < 2021-09
dahuasecurity/asi7223x-a-t1_firmware < 2021-09
dahuasecurity/asi7223x-a_firmware < 2021-09
dahuasecurity/ipc-hdbw2230e-s-s2_firmware < 2022-04
dahuasecurity/ipc-hdbw2231e-s-s2_firmware < 2022-04
dahuasecurity/ipc-hdbw2231f-as-s2_firmware < 2022-04
dahuasecurity/ipc-hdbw2231r-zas-s2_firmware < 2022-04
dahuasecurity/ipc-hdbw2231r-zs-s2_firmware < 2022-04
dahuasecurity/ipc-hdbw2431e-s-s2_firmware < 2022-04
... and 30 more
Published Jun 28, 2022
Tracked Since Feb 18, 2026