nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-50909 CVE-2022-50909
HIGH
Algo 8028 Control Panel - Remote Code Execution (RCE) (Authenticated)
Record summary
CVE-2022-50909 has a selected CVSS score of 8.6 (high); EIP currently links 1 catalogued exploit.
Description
Algo 8028 Control Panel version 3.3.3 contains a command injection vulnerability in the fm-data.lua endpoint that allows authenticated attackers to execute arbitrary commands. Attackers can exploit the insecure 'source' parameter by injecting commands that are executed with root privileges, enabling remote code execution through a crafted POST request.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 14, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Algo 8028Browse Algo Solutions / Algo 8028 | CVE List | 3.3.3 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBAlgo 8028 Control Panel - Remote Code Execution (RCE) (Authenticated)ExploitDB exploitby Filip CarlssonNot analyzed1 file
References
5Algo Solutions Official Homepageproduct
https://www.algosolutions.com/ Algo 8028 Firmware Downloadsproduct
https://www.algosolutions.com/firmware-downloads/8028-firmware-selection ExploitDB-50960exploit
https://www.exploit-db.com/exploits/50960 VulnCheck Advisory: Algo 8028 Control Panel - Remote Code Execution (RCE) (Authenticated)Third-party advisory
https://www.vulncheck.com/advisories/algo-control-panel-remote-code-execution-rce-authenticated