CVE-2022-50893
CRITICALVIAVIWEB Wallpaper Admin 1.0 - RCE
Title source: llmDescription
VIAVIWEB Wallpaper Admin 1.0 contains an unauthenticated remote code execution vulnerability in the image upload functionality. Attackers can upload a malicious PHP file through the add_gallery_image.php endpoint to execute arbitrary code on the server.
Exploits (1)
Scores
CVSS v3
9.8
EPSS
0.0112
EPSS Percentile
78.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-434
Status
published
Products (2)
VIAVIWEB/VIAVIWEB Wallpaper Admin
1.0
viaviweb/wallpaper_admin
1.0
Published
Jan 13, 2026
Tracked Since
Feb 18, 2026