CVE-2022-44149 EXPLOIT
8.8
HIGH · CVSS 3.1 · EPSS 64.4% (pctl 99)
Patch early
A public exploit exists.
Description
The web service on Nexxt Amp300 ARN02304U8 42.103.1.5095 and 80.103.2.5045 devices allows remote OS command execution by placing &telnetd in the JSON host field to the ping feature of the goform/sysTools component. Authentication is required
Scoring
| CVSS | 8.8 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 64.35% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-78 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2023-01-06 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| nexxtsolutions | amp300 |
| nexxtsolutions | amp300 firmware |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Nexxt Router Firmware 42.103.1.5095 - Remote Code Execution (RCE) (Authenticated) | 2023-04-01 |
References
- http://packetstormsecurity.com/files/170366/Nexxt-Router-Firmware-42.103.1.5095-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/170366/Nexxt-Router-Firmware-80.103.2.5045-Remote-Code-Execution.html
- https://cxsecurity.com/issue/WLB-2023010006
- https://packetstormsecurity.com/files/170366/Nexxt-Router-Firmware-42.103.1.5095-Remote-Code-Execution.html
- https://www.nexxtsolutions.com/connectivity/search/?q=ARN02304U8
- http://packetstormsecurity.com/files/170366/Nexxt-Router-Firmware-42.103.1.5095-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/170366/Nexxt-Router-Firmware-80.103.2.5045-Remote-Code-Execution.html
- https://cxsecurity.com/issue/WLB-2023010006
- https://packetstormsecurity.com/files/170366/Nexxt-Router-Firmware-42.103.1.5095-Remote-Code-Execution.html
- https://www.nexxtsolutions.com/connectivity/search/?q=ARN02304U8
→ the Explorer · watch your stack · NVD