CVE-2022-37680

HIGH

Hitachi HC-IP9100HD Firmware < 1.07 - Unauthenticated Remote Reboot via /ptipupgrade.cgi

Title source: llm
STIX 2.1

Description

An improper authentication for critical function issue in Hitachi Kokusai Electric Network products for monitoring system (Camera, Decoder and Encoder) and bellow allows attckers to remotely reboot the device via a crafted POST request to the endpoint /ptipupgrade.cgi. Security information ID hitachi-sec-2022-001 contains fixes for the issue.

References (2)

Core 2

Scores

CVSS v3 7.5
EPSS 0.0031
EPSS Percentile 54.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-306
Status published
Products (1)
hitachi/hc-ip9100hd_firmware < 1.07
Published Aug 29, 2022
Tracked Since Feb 18, 2026