CVE-2022-36553
hytec hwl-2511-ss_firmware Improper Neutralization of Special Elements used in a Command ('Command Injection')
Record summary
CVE-2022-36553 has a selected CVSS score of 9.8 (critical); EIP currently links 1 repository PoC and 1 Nuclei template.
Description
Hytec Inter HWL-2511-SS v1.05 and below was discovered to contain a command injection vulnerability via the component /www/cgi-bin/popen.cgi.
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
hwl-2511-ss_firmwareBrowse hytec / hwl-2511-ss_firmware | VulnCheck | Version data not supplied | |
Proofs of concept
1Repository PoCs
GitHub0xNslabs/CVE-2022-36553-PoCRepository PoCby 0xNslabsStars: 6Not analyzed2 files
Nuclei templates
1ProjectDiscoveryCRITICALHytec Inter HWL-2511-SS - Remote Command ExecutionCVSS 9.8
Hytec Inter HWL-2511-SS v1.05 and below was discovered to contain a command injection vulnerability via the component /www/cgi-bin/popen.cgi.
Impact
Unauthenticated attackers can execute arbitrary commands on the Hytec Inter HWL-2511-SS cellular router through command injection in the popen.cgi endpoint, potentially gaining complete control over the device and connected network infrastructure.
Remediation
Update Hytec Inter HWL-2511-SS firmware to a version later than 1.05 that properly sanitizes command parameters in popen.cgi.
Source: ProjectDiscovery