CVE-2022-28369
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 does not validate the user-provided URL within the crtcmode function's enable_ssh sub-operation of the crtcrpc JSON listener (found at /lib/functions/wnc_jsonsh/crtcmode.sh) A remote attacker on the local network can provide a malicious URL. The data (found at that URL) is written to /usr/sbin/dropbear and then executed as root.
Verizon 5G Home LVSKIHP InDoorUnit (IDU) versión 3.4.66.162, no comprueba la URL proporcionada por el usuario en la sub operación enable_ssh de la función crtcmode del listener JSON de crtcrpc (que es encontrada en /lib/functions/wnc_jsonsh/crtcmode.sh) Un atacante remoto en la red local puede proporcionar una URL maliciosa. Los datos (encontrados en esa URL) son escritos en /usr/sbin/dropbear y luego son ejecutados como root
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-04-03 CVE Reserved
- 2022-07-14 CVE Published
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- 2025-04-08 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-434: Unrestricted Upload of File with Dangerous Type
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/JousterL/SecWriteups/blob/main/Verizon%20LVSKIHP%205G%20Modem/readme.md | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.verizon.com/info/reportsecurityvulnerability | 2022-07-21 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Verizon Search vendor "Verizon" | Lvskihp Indoorunit Firmware Search vendor "Verizon" for product "Lvskihp Indoorunit Firmware" | 3.4.66.162 Search vendor "Verizon" for product "Lvskihp Indoorunit Firmware" and version "3.4.66.162" | - |
Affected
| in | Verizon Search vendor "Verizon" | Lvskihp Indoorunit Search vendor "Verizon" for product "Lvskihp Indoorunit" | - | - |
Safe
|