CVE-2022-40005

HIGH WAF: High
CVSS 8.8 Published: 2022-12-25
CWE-78 CWE-78

Intelbras WiFiber 120AC inMesh before 1-1-220826 allows command injection by authenticated users, as demonstrated by the /boaform/formPing6 and /boaform/formTracert URIs for ping and traceroute.

WAF Coverage Analysis

OS Command Injection High WAF Coverage

OWASP: A03:2021 Injection

932xxx - Remote Code Execution
OS Command Injection High WAF Coverage

OWASP: A03:2021 Injection

932xxx - Remote Code Execution

Affected Software

VendorProductVersion
intelbraswifiber_120ac_inmesh_firmware1.1-220216 - 1.1-220826

References

Back to CVE Database