CVE Vulnerabilities

CVE-2022-29888

Active Debug Code

Published: Nov 09, 2022 | Modified: Nov 21, 2024
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A leftover debug code vulnerability exists in the httpd port 4444 upload.cgi functionality of InHand Networks InRouter302 V3.5.45. A specially-crafted HTTP request can lead to arbitrary file deletion. An attacker can send an HTTP request to trigger this vulnerability.

Weakness

The product is released with debugging code still enabled or active.

Affected Software

NameVendorStart VersionEnd Version
Ir302_firmwareInhandnetworks3.5.45 (including)3.5.45 (including)

Potential Mitigations

References