CRITICAL🇵🇱 Wersja polska

CVE-2022-32203

CVSS 9.8v3.1pub. 2024-12-20upd. 2025-01-10

There is a command injection vulnerability in Huawei terminal printer product. Successful exploitation could result in the highest privileges of the printer. (Vulnerability ID: HWPSIRT-2022-51773) This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2022-32203.

🤖 AI Analysis
How it works

The vulnerability consists of improper validation of input data, which enables injection of malicious system commands (command injection, CWE-77). An attacker can send specially crafted data to a vulnerable component of the device. The attack vector is network-based, requires no authentication or user interaction, making exploitation exceptionally simple.

Impact

An attacker can obtain the highest privileges on the printer device, enabling full control over the device, including configuration modification, reading transmitted data, and potential use of the device as an entry point to the internal network.

Mitigation & patch

Apply patches available from the manufacturer according to the references: https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20220601-01-6b47c6b6-en

Who is affected

Huawei CV81-WDM Firmware and Huawei CV81-WDM — specific versions indicated in manufacturer references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Huawei Cv81 Wdm

    HW
    Huawei
    all versions
  • Huawei Cv81 Wdm Firmware

    OS
    Huawei
    01.70.49.29.46
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2022-29797CRITICAL9.8PL ✓same product

Buffer overflow w Huawei CV81-WDM umożliwiający privilege escalation

CVE-2022-32144HIGH8.6same product

There is an insufficient input verification vulnerability in Huawei product. Successful exploitation of this v...

CVE-2022-32204HIGH7.5same product

There is an improper input verification vulnerability in Huawei printer product. Successful exploitation of th...

CVE-2022-34159HIGH7.5same product

Huawei printers have an input verification vulnerability. Successful exploitation of this vulnerability may ca...

CVE-2022-29798HIGH7.5same product

There is a denial of service vulnerability in CV81-WDM FW versions 01.70.49.29.46. Successful exploitation cou...