CVE-2022-28374
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 does not property sanitize user-controlled parameters within the DMACC URLs on the Settings page of the Engineering portal. An authenticated remote attacker on the local network can inject shell metacharacters into /usr/lib/lua/5.1/luci/controller/admin/settings.lua to achieve remote code execution as root.
Verizon 5G Home LVSKIHP OutDoorUnit (ODU) versión 3.33.101.0, no sanea apropiadamente los parámetros controlados por el usuario dentro de las URLs DMACC en la página de Ajustes del portal de Ingeniería. Un atacante remoto autenticado en la red local puede inyectar meta caracteres de shell en el archivo /usr/lib/lua/5.1/luci/controller/admin/settings.lua para lograr una ejecución de código remota como root
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-04-03 CVE Reserved
- 2022-07-14 CVE Published
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- 2025-04-08 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/JousterL/SecWriteups/blob/main/Verizon%20LVSKIHP%205G%20Modem/readme.md | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.verizon.com/info/reportsecurityvulnerability | 2023-08-08 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Verizon Search vendor "Verizon" | Lvskihp Outdoorunit Firmware Search vendor "Verizon" for product "Lvskihp Outdoorunit Firmware" | 3.33.101.0 Search vendor "Verizon" for product "Lvskihp Outdoorunit Firmware" and version "3.33.101.0" | - |
Affected
| in | Verizon Search vendor "Verizon" | Lvskihp Outdoorunit Search vendor "Verizon" for product "Lvskihp Outdoorunit" | - | - |
Safe
|