Information Disclosure in IP-COM Router Firmware
CVE-2022-43366
7.5HIGH
What is CVE-2022-43366?
The IP-COM EW9 router firmware version 15.11.0.14 contains multiple interfaces that allow unauthenticated attackers to gain access to sensitive information, including user login details and system configurations. The exposed interfaces such as checkLoginUser, ate, telnet, version, setDebugCfg, and boot can lead to unauthorized data exposure, potentially allowing attackers to exploit the information for further attacks. Users of affected versions should take immediate action to secure their devices.
