CVE-2022-42156

CWE-77Command Injection8 documents4 sources
Severity
8.8HIGH
EPSS
9.2%
top 7.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 13
Latest updateJan 6

Description

D-Link COVR 1200,1203 v1.08 was discovered to contain a command injection vulnerability via the tomography_ping_number parameter at function SetNetworkTomographySettings.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

🔴Vulnerability Details

7
OSV
linux-raspi-5.4 vulnerabilities2025-01-06
OSV
linux-iot vulnerabilities2024-12-20
OSV
linux-aws, linux-aws-5.4 vulnerabilities2024-12-17
OSV
linux-bluefield, linux-oracle, linux-oracle-5.4 vulnerabilities2024-12-17
OSV
linux, linux-gcp, linux-gcp-5.4, linux-hwe-5.4, linux-ibm, linux-ibm-5.4, linux-kvm, linux-raspi, linux-xilinx-zynqmp vulnerabilities2024-12-12
CVE-2022-42156 (HIGH CVSS 8.8) | D-Link COVR 1200,1203 v1.08 was dis | cvebase.io