CVE-2022-36642
CRITICAL EXPLOITED NUCLEITelosalliance Omnia Mpx Node Firmware < 1.5.0 - Missing Authorization
Title source: ruleDescription
A local file disclosure vulnerability in /appConfig/userDB.json of Telos Alliance Omnia MPX Node through 1.0.0-1.4.9 allows attackers to access users credentials which makes him able to gain initial access to the control panel with high privilege because the cleartext storage of sensitive information which can be unlatched by exploiting the LFD vulnerability.
Exploits (1)
exploitdb
WORKING POC
by Momen Eldawakhly · textremotehardware
https://www.exploit-db.com/exploits/50996
Nuclei Templates (1)
Omnia MPX 1.5.0+r1 - Local File Inclusion
CRITICALVERIFIEDby arafatansari,ritikchaddha,For3stCo1d
Shodan:
http.title:"Omnia MPX Node | Login" || http.title:"omnia mpx node | login"
FOFA:
title="omnia mpx node | login"
References (5)
Scores
CVSS v3
9.8
EPSS
0.7072
EPSS Percentile
98.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
VulnCheck KEV
2023-11-13
CWE
CWE-862
Status
published
Products (2)
telosalliance/omnia_mpx_node_firmware
1.5.0 (2 CPE variants)
telosalliance/omnia_mpx_node_firmware
1.0.0 - 1.5.0
Published
Sep 02, 2022
Tracked Since
Feb 18, 2026