HIGH🇵🇱 Wersja polska

CVE-2022-21182

CVSS 8.8v3.1pub. 2022-05-12upd. 2024-11-21

A privilege escalation vulnerability exists in the router configuration import functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted HTTP request can lead to increased privileges. An attacker can send an HTTP request to trigger this vulnerability.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Inhandnetworks Inrouter302

    HW
    Inhandnetworks
    all versions
  • Inhandnetworks Inrouter302 Firmware

    OS
    Inhandnetworks
    ≤ 3.5.4
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
LPE
CWE
References

Related vulnerabilities

CVE-2023-22600CRITICAL10.0PL ✓same product

Nieautoryzowany dostęp do MQTT w routerach InHand Networks InRouter 302/615

CVE-2023-22601CRITICAL10.0PL ✓same product

InHand Networks InRouter 302/615 — słaba losowość MQTT ClientID

CVE-2022-25932CRITICAL9.8PL ✓same product

Niekompletne poprawki privilege escalation w InHand Networks InRouter302

CVE-2023-22598HIGH7.2same product

InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-...

CVE-2023-22599HIGH7.0same product

InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-...