CVE-2022-35733
CVE-2022-35733
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 1.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
23 Aug 2022Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Missing authentication for critical function vulnerability in UNIMO Technology digital video recorders (UDR-JA1004/JA1008/JA1016 firmware versions v1.0.20.13 and earlier, and UDR-JA1016 firmware versions v2.0.20.13 and earlier) allows a remote unauthenticated attacker to execute an arbitrary OS command by sending a specially crafted request to the affected device web interface.
Affected products
UNIMO Technology Co., Ltd · UNIMO Technology digital video recorders UDR-JA1004/JA1008/JA1016 and UDR-JA1016Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →