CVE-2022-34753 – Schneider Electric SpaceLogic C-Bus Home Controller (5200WHC2) Remote Root
https://notcve.org/view.php?id=CVE-2022-34753
A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote root exploit when the command is compromised. Affected Products: SpaceLogic C-Bus Home Controller (5200WHC2), formerly known as C-Bus Wiser Homer Controller MK2 (V1.31.460 and prior) Una CWE-78: Se presenta una vulnerabilidad de Neutralización Inapropiada de Elementos Especiales usados en un Comando del Sistema Operativo ("Inyección de comandos del SO") que podría causar una explotación remota de root cuando el comando está comprometido. Productos afectados: SpaceLogic C-Bus Home Controller (5200WHC2), anteriormente conocido como C-Bus Wiser Homer Controller MK2 (versiones V1.31.460 y anteriores) • https://github.com/K3ysTr0K3R/CVE-2022-34753-EXPLOIT http://packetstormsecurity.com/files/167783/Schneider-Electric-SpaceLogic-C-Bus-Home-Controller-5200WHC2-Remote-Root.html https://download.schneider-electric.com/files?p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2022-193-02_SpaceLogic-C-Bus-Home-Controller-Wiser_MK2_Security_Notification.pdf • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •