Remote Code Execution Vulnerability in Verizon 5G Home Outdoor Unit
CVE-2022-28375
9.8CRITICAL
What is CVE-2022-28375?
The Verizon 5G Home LVSKIHP Outdoor Unit (ODU) version 3.33.101.0 has a severe vulnerability due to improper sanitization of user-controlled parameters within the crtcswitchsimprofile function of the crtcrpc JSON listener. This flaw enables a remote attacker on the local network to inject shell metacharacters into the rpc.lua script located at /usr/lib/lua/5.1/luci/controller/. Successful exploitation of this vulnerability can lead to remote code execution with root privileges, potentially compromising the integrity and security of the affected device.
