cyberdanube.com
https://cyberdanube.com/en/authenticated-command-injection-in-intelbras-wifiber-120ac-inmesh CVE-2022-40005
HIGH
intelbras wifiber_120ac_inmesh_firmware Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Record summary
CVE-2022-40005 has a selected CVSS score of 8.8 (high).
Description
Intelbras WiFiber 120AC inMesh before 1-1-220826 allows command injection by authenticated users, as demonstrated by the /boaform/formPing6 and /boaform/formTracert URIs for ping and traceroute.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jun 22, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 14, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
wifiber_120ac_inmesh_firmwareBrowse intelbras / wifiber_120ac_inmesh_firmware | VulnCheck | Version data not supplied | |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-40005 seclists.org
https://seclists.org/fulldisclosure/2022/Dec/13