CVE Published: 23/08/2022 |
CVE Updated: 03/08/2024 |
CVE Year: 2022 Source: jpcert |
Vendor: UNIMO Technology Co., Ltd |
Product: UNIMO Technology digital video recorders UDR-JA1004/JA1008/JA1016 and UDR-JA1016 Status : PUBLISHED
CVE-2022-35733 Description
Missing authentication for critical function vulnerability in UNIMO Technology digital video recorders (UDR-JA1004/JA1008/JA1016 firmware versions v1.0.20.13 and earlier, and UDR-JA1016 firmware versions v2.0.20.13 and earlier) allows a remote unauthenticated attacker to execute an arbitrary OS command by sending a specially crafted request to the affected device web interface.