CVE-2022-34538
HIGH EXPLOITED IN THE WILDDigital Watchdog MEGApix IP Cameras A7.2.2_20211029 - OS Command Injection via /admin/vca/bia/addacph.cgi
Title source: llmExploitation Summary
CVE-2022-34538 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io).
Description
Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a command injection vulnerability in the component /admin/vca/bia/addacph.cgi. This vulnerability is exploitable via a crafted POST request.
References (1)
Core 1
Core References
Third Party Advisory x_refsource_misc
https://gist.github.com/secgrant/820faeeaa0cb4889edaa1d6fef83deab
Scores
CVSS v3
8.8
EPSS
0.0273
EPSS Percentile
84.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
VulnCheck KEV
2022-12-06
InTheWild.io
2022-12-21
CWE
CWE-78
Status
published
Products (1)
dw/megapix_firmware
4.2.0.32842
Published
Jul 19, 2022
Tracked Since
Feb 18, 2026