Record summary

CVE-2022-35733 has a selected CVSS score of 9.8 (critical).

Description

Missing authentication for critical function vulnerability in UNIMO Technology digital video recorders (UDR-JA1004/JA1008/JA1016 firmware versions v1.0.20.13 and earlier, and UDR-JA1016 firmware versions v2.0.20.13 and earlier) allows a remote unauthenticated attacker to execute an arbitrary OS command by sending a specially crafted request to the affected device web interface.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jun 19, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Affected products and versions

2
ProductSourceVersion rangeStatus

UNIMO Technology digital video recorders UDR-JA1004/JA1008/JA1016 and UDR-JA1016

Browse UNIMO Technology Co., Ltd / UNIMO Technology digital video recorders UDR-JA1004/JA1008/JA1016 and UDR-JA1016
CVE ListUDR-JA1004/JA1008/JA1016 firmware versions v1.0.20.13 and earlier, and UDR-JA1016 firmware versions v2.0.20.13 and earlieraffected
VulnCheckVersion data not supplied

References

3