CVE-2022-33948 Vulnerability Details

  /     /     /  

CVE-2022-33948 Metadata Quick Info

CVE Published: 04/07/2022 | CVE Updated: 03/08/2024 | CVE Year: 2022
Source: jpcert | Vendor: KDDI CORPORATION | Product: HOME SPOT CUBE2
Status : PUBLISHED

CVE-2022-33948 Description

HOME SPOT CUBE2 V102 contains an OS command injection vulnerability due to improper processing of data received from DHCP server. An adjacent attacker may execute an arbitrary OS command on the product if a malicious DHCP server is placed on the WAN side of the product.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: OS Command Injection
Source: KDDI CORPORATION

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).