cbcvebase.
CVE-2022-45140
published 2023-02-27

CVE-2022-45140: The configuration backend allows an unauthenticated user to write arbitrary data with root privileges to the storage, which could lead to unauthenticated…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
The configuration backend allows an unauthenticated user to write arbitrary data with root privileges to the storage, which could lead to unauthenticated remote code execution and full system compromise.

Affected

35 ranges· showing 25
VendorProductVersion rangeFixed in
wago751-9301_firmware
wago751-9301_firmware
wago751-9301_firmware>= 16 < 2222
wago752-8303_8000-002_firmware
wago752-8303_8000-002_firmware
wago752-8303_8000-002_firmware>= 18 < 2222
wagocompact_controller_cc100
wagocompact_controller_cc100>= FW16 < FW22FW22
wagoedge_controller
wagoedge_controller>= FW16 < FW22FW22
wagopfc100
wagopfc100>= FW16 < FW22FW22
wagopfc100_firmware
wagopfc100_firmware
wagopfc100_firmware>= 16 < 2222
wagopfc200
wagopfc200>= FW16 < FW22FW22
wagopfc200_firmware
wagopfc200_firmware
wagopfc200_firmware>= 16 < 2222
wagotouch_panel_600_advanced_firmware
wagotouch_panel_600_advanced_firmware
wagotouch_panel_600_advanced_firmware>= 16 < 2222
wagotouch_panel_600_advanced_line
wagotouch_panel_600_advanced_line>= FW16 < FW22FW22