HIGH

CVE-2022-45600

CVSS v3

8.8

HIGH

EPSS Score

25.6%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

Aztech WMB250AC Mesh Routers Firmware Version 016 2020 devices improperly manage sessions, which allows remote attackers to bypass authentication in opportunistic circumstances and execute arbitrary commands with administrator privileges by leveraging an existing web portal login.

Technical details

Published
2/22/2023

Frequently asked questions

What is CVE-2022-45600?

Aztech WMB250AC Mesh Routers Firmware Version 016 2020 devices improperly manage sessions, which allows remote attackers to bypass authentication in opportunistic circumstances and execute arbitrary commands with administrator privileges by leveraging an existing web portal login.

Is CVE-2022-45600 actively exploited?

Active exploitation of CVE-2022-45600 has not been confirmed. The EPSS score is 25.6%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2022-45600?

CVE-2022-45600 has a CVSS v3 base score of 8.8 (HIGH severity).

Is CVE-2022-45600 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.