CRITICAL

CVE-2022-29337

CVSS v3

9.8

CRITICAL

EPSS Score

30.4%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

C-DATA FD702XW-X-R430 v2.1.13_X001 was discovered to contain a command injection vulnerability via the va_cmd parameter in formlanipv6. This vulnerability allows attackers to execute arbitrary commands via a crafted HTTP request.

Technical details

Published
5/24/2022

Frequently asked questions

What is CVE-2022-29337?

C-DATA FD702XW-X-R430 v2.1.13_X001 was discovered to contain a command injection vulnerability via the va_cmd parameter in formlanipv6. This vulnerability allows attackers to execute arbitrary commands via a crafted HTTP request.

Is CVE-2022-29337 actively exploited?

Active exploitation of CVE-2022-29337 has not been confirmed. The EPSS score is 30.4%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2022-29337?

CVE-2022-29337 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2022-29337 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.