Remote Code Execution Vulnerability in Verizon 5G Home InDoor Unit
CVE-2022-28369

9.8CRITICAL

Key Information:

Vendor

Verizon

Vendor
CVE Published:
14 July 2022

What is CVE-2022-28369?

The Verizon 5G Home LVSKIHP InDoor Unit has an unvalidated user input flaw that allows local network attackers to provide a malicious URL. This URL can send harmful data to /usr/sbin/dropbear, which may be executed with root privileges, compromising the device's integrity and overall network security.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.