peter bassill · operator
$ cve CVE-2022-24629 JSON

CVE-2022-24629 EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 37.2% (pctl 98)

Patch early

A public exploit exists.

Description

An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. Remote code execution can be achieved via directory traversal in the dir parameter of the file upload functionality of BrowseFiles.php. An attacker can upload a .php file to WebAdmin/admin/AudioCodes_files/ajax/.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS37.25% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2023-05-29
Last modified2026-06-17

Affected (1)

VendorProduct
audiocodesdevice manager express

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD