PT-2026-2401 · Prowise · Prowise Reflect

Rik Lutz

·

Published

2026-01-13

·

Updated

2026-01-30

·

CVE-2022-50925

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Prowise Reflect version 1.0.9
Description Prowise Reflect version 1.0.9 has a remote keystroke injection issue. An exposed WebSocket on port 8082 allows attackers to send keyboard events. Malicious web pages can be created to inject keystrokes, enabling attackers to open applications and type arbitrary text by sending specific WebSocket messages.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Origin Validation Error

Weakness Enumeration

Related Identifiers

CVE-2022-50925

Affected Products

Prowise Reflect