CVE-2022-45699
apsystems ecu-r_firmware Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Record summary
CVE-2022-45699 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
Command injection in the administration interface in APSystems ECU-R version 5203 allows a remote unauthenticated attacker to execute arbitrary commands as root using the timezone parameter.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jun 22, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 24, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
ecu-r_firmwareBrowse apsystems / ecu-r_firmware | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICALAPsystems ECU-R Firmware - Command InjectionCVSS 9.8
Command injection in the administration interface in APSystems ECU-R version 5203 allows a remote unauthenticated attacker to execute arbitrary commands as root using the timezone parameter.
Impact
Unauthenticated attackers can execute arbitrary commands with root privileges through the timezone parameter in the administration interface, potentially compromising the entire solar power management system and connected infrastructure.
Remediation
Upgrade APsystems ECU-R firmware to a patched version that properly sanitizes the timezone parameter and validates input to prevent command injection.
Source: ProjectDiscovery