System Command Injection Vulnerability in Huawei Printers
CVE-2022-48472

9.8CRITICAL

Key Information:

Vendor
Huawei
Vendor
CVE Published:
16 June 2023

Summary

A vulnerability present in certain Huawei printers allows for system command injection, which can be exploited to execute arbitrary code remotely. This could potentially compromise the integrity of the device and the network it operates within. Specific affected versions include BiSheng-WNM OTA-BiSheng-FW-2.0.0.211-beta, BW FM 3.0.0.325, and BW FM 2.0.0.211. Users are advised to review security advisories and implement necessary updates to mitigate risks.

Affected Version(s)

BiSheng-WNM OTA-BiSheng-FW-2.0.0.211-beta

BiSheng-WNM BiSheng-WNM FW 3.0.0.325

BiSheng-WNM BiSheng-WNM FW 2.0.0.211

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.