Record summary

CVE-2022-45699 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

Command injection in the administration interface in APSystems ECU-R version 5203 allows a remote unauthenticated attacker to execute arbitrary commands as root using the timezone parameter.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jun 22, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 24, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryCRITICALAPsystems ECU-R Firmware - Command InjectionCVSS 9.8

Command injection in the administration interface in APSystems ECU-R version 5203 allows a remote unauthenticated attacker to execute arbitrary commands as root using the timezone parameter.

Impact

Unauthenticated attackers can execute arbitrary commands with root privileges through the timezone parameter in the administration interface, potentially compromising the entire solar power management system and connected infrastructure.

Remediation

Upgrade APsystems ECU-R firmware to a patched version that properly sanitizes the timezone parameter and validates input to prevent command injection.

WeaknessesCWE-78CWE-94
Authorspussycat0x
Template tagscvecve2022rceapsystemsvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:o:apsystems:ecu-r_firmware:5203:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

4