Record summary

CVE-2022-40881 has a selected CVSS score of 9.8 (critical); EIP currently links 1 repository PoC and 1 Nuclei template.

Description

SolarView Compact 6.00 was discovered to contain a command injection vulnerability via network_test.php

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Nov 13, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
1
Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 29, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Proofs of concept

1

Repository PoCs

GitHubyilin1203/CVE-2022-40881Repository PoCby yilin1203Stars: 2Not analyzed2 files

2.5 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryCRITICALSolarView 6.00 - Remote Command ExecutionCVSS 9.8

SolarView Compact 6.00 is vulnerable to a command injection via network_test.php.

Impact

Successful exploitation of this vulnerability allows an attacker to execute arbitrary commands on the target system.

Remediation

Apply the latest patch or upgrade to a non-vulnerable version of SolarView.

WeaknessesCWE-77
AuthorsFor3stCo1d
Template tagscvecve2022solarviewrcelficontecvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:h:contec:solarview_compact:-:*:*:*:*:*:*:*
Shodan: http.favicon.hash:"-244067125"
Shodan: cpe:"cpe:2.3:h:contec:solarview_compact"

Source: ProjectDiscovery

References

2