PT-2022-6990 · Unknown · Solarview Compact
Published
2022-05-12
·
Updated
2025-11-03
·
CVE-2022-29303
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SolarView Compact version 6.00
Description
The issue exists due to the failure to neutralize special elements used in an operating system command in the conf mail.php component of the SolarView Compact device. This can allow an attacker to execute arbitrary commands. The vulnerability can be exploited via the conf mail.php file, potentially allowing for command injection attacks.
Recommendations
For SolarView Compact version 6.00, consider disabling access to the conf mail.php file as a temporary workaround until a patch is available. Restricting access to this component can help minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Solarview Compact