Command Injection Vulnerability in IP-COM M50 Product
CVE-2022-45717
9.8CRITICAL
What is CVE-2022-45717?
The IP-COM M50 device, specifically version V15.11.0.33, has been identified with a command injection vulnerability. This flaw exists in the handling of the usbPartitionName parameter within the formSetUSBPartitionUmount function. Attackers can exploit this vulnerability by sending a specially crafted GET request, which may allow for unauthorized command execution on the affected device.
