CVE-2022-45600

HIGH

Aztech WMB250AC Firmware 016 2020 - Unauthenticated Remote Code Execution via Session Bypass

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2022-45600. PoCs published by ethancunt.

AI-analyzed exploit summary This PoC demonstrates a command injection vulnerability in Aztech WMB250AC Wireless Mesh Routers, allowing authenticated users to execute arbitrary shell commands as root via the 'id' GET parameter in multiple webpages. The exploit overwrites /etc/passwd to create a backdoor user for telnet access.

Description

Aztech WMB250AC Mesh Routers Firmware Version 016 2020 devices improperly manage sessions, which allows remote attackers to bypass authentication in opportunistic circumstances and execute arbitrary commands with administrator privileges by leveraging an existing web portal login.

Exploits (1)

nomisec WORKING POC
by ethancunt · poc
https://github.com/ethancunt/CVE-2022-45600

This PoC demonstrates a command injection vulnerability in Aztech WMB250AC Wireless Mesh Routers, allowing authenticated users to execute arbitrary shell commands as root via the 'id' GET parameter in multiple webpages. The exploit overwrites /etc/passwd to create a backdoor user for telnet access.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Aztech WMB250AC Wireless Mesh Routers (2020 Release firmware)
Auth required
Prerequisites: Network access to the router's web interface · Valid admin credentials (default: admin:admin) · Router running vulnerable firmware
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit, Third Party Advisory
https://github.com/ethancunt/CVE-2022-45600

Scores

CVSS v3 8.8
EPSS 0.0235
EPSS Percentile 81.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-77
Status published
Products (1)
aztech/wmb250ac_firmware 016_2020
Published Feb 22, 2023
Tracked Since Feb 18, 2026