CVE-2022-44149
HIGH 8.8EPSS 64.4%
The web service on Nexxt Amp300 ARN02304U8 42.103.1.5095 and 80.103.2.5045 devices allows remote OS command execution by placing &telnetd in the JSON host field to the ping feature of the goform/sysTools component. Authentication is required
- CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS
- 64.35% chance of exploitation in the next 30 days, 99th percentile
- Published
- 2023-01-06
- Updated
- 2025-04-09
Proof-of-concept exploits (6)
- http://packetstormsecurity.com/files/170366/Nexxt-Router-Firmware-42.103.1.5095-Remote-Co…
- http://packetstormsecurity.com/files/170366/Nexxt-Router-Firmware-80.103.2.5045-Remote-Co…
- https://packetstormsecurity.com/files/170366/Nexxt-Router-Firmware-42.103.1.5095-Remote-C…
- geniuszly/CVE-2022-441495★ · 2024-08-09
- geniuszlyy/CVE-2022-441495★ · 2024-08-09
- yerodin/CVE-2022-441490★ · 2023-01-25