Skip to main content
HIGH

CVE-2022-34906

CVSS v3

7.5

HIGH

EPSS Score

10.6 %

exploit probability, as of 2026-09-25

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

A hard-coded cryptographic key is used in FileWave before 14.6.3 and 14.7.x before 14.7.2. Exploitation could allow an unauthenticated actor to decrypt sensitive information saved in FileWave, and even send crafted requests.

Technical details

Published
2022-07-25

Frequently asked questions

What is CVE-2022-34906?

A hard-coded cryptographic key is used in FileWave before 14.6.3 and 14.7.x before 14.7.2. Exploitation could allow an unauthenticated actor to decrypt sensitive information saved in FileWave, and even send crafted requests.

Is CVE-2022-34906 actively exploited?

Active exploitation of CVE-2022-34906 has not been confirmed. Its EPSS score was 10.6% on 2026-09-25, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2022-34906?

CVE-2022-34906 has a CVSS v3 base score of 7.5 (HIGH severity).

Is CVE-2022-34906 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key