CVE-2022-4616
The webserver in Delta DX-3021 versions prior to 1.24 is vulnerable to command injection through the network diagnosis page. This vulnerability could allow a remote unauthenticated user to add files, delete files, and change file permissions.
- Affected products
- Delta Dx-3021
- Deltaww dx-3021l9 Firmware
- < 1.24
- CVSS 3.1
- 9.1 CRITICAL
- EPSS
- 4.8% (91th percentile)
- Weakness
- CWE-77
- NVD status
- Modified
- Published
- 2023-01-12
Fix
Delta fixed this vulnerability and released a new patch, which is available on the Delta download center https://downloadcenter.deltaww.com/en-US/DownloadCenter .
CVE-2022-4616 at NVD
2 known exploits for CVE-2022-4616
Proof-of-concept code and exploit modules indexed by Sploitus