PoC Index

CVE-2022-42055

MEDIUM 6.5EPSS 1.7%

Multiple command injection vulnerabilities in GL.iNet GoodCloud IoT Device Management System Version 1.00.220412.00 via the ping and traceroute tools allow attackers to read arbitrary files on the system.

CVSS v3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS v3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
1.71% chance of exploitation in the next 30 days, 76th percentile
Published
2022-10-27
Updated
2025-05-07

Proof-of-concept exploits (1)

References

Related