Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-40282


The web server of Hirschmann BAT-C2 before 09.13.01.00R04 allows authenticated command injection. This allows an authenticated attacker to pass commands to the shell of the system because the dir parameter of the FsCreateDir Ajax function is not sufficiently sanitized. The vendor's ID is BSECV-2022-21.


Published

2022-11-25T05:15:13.010

Last Modified

2025-04-29T15:15:48.383

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

Weaknesses
  • Type: Primary
    NVD-CWE-Other
  • Type: Secondary
    CWE-77

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System belden hirschmann_bat-c2_firmware < 09.13.00r04 Yes
Hardware belden hirschmann_bat-c2 - No

References