PT-2022-15936 · Shenzhen Ejoin Information Technology Co. · Acom532+2

Published

2022-05-09

·

Updated

2023-08-08

·

CVE-2022-23332

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Shenzhen Ejoin Information Technology Co., Ltd. ACOM508/ACOM516/ACOM532 versions 609-915-041-100-020
Description A command injection issue exists in the Manual Ping Form of the Web UI, allowing a remote attacker to inject arbitrary code via a field.
Recommendations For version 609-915-041-100-020, consider restricting access to the Manual Ping Form in the Web UI to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2022-23332

Affected Products

Acom508
Acom516
Acom532