CRITICAL

CVE-2022-29303

Contec Sv Cpt Mc310 Firmware 2022-05-12 CVSS v3.1
CVSS
9.8
KEV

Description

SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php.

Summary dbcve.org

SolarView Compact version 6.00 contains an OS command injection vulnerability in conf_mail.php, allowing a remote, unauthenticated attacker to inject and execute arbitrary operating system commands on the underlying host. The CVSS 9.8 score indicates the flaw is network-exploitable with low attack complexity and requires no privileges or user interaction, resulting in full system compromise.

Mitigation

Upgrade SolarView Compact to a vendor-patched version if available; otherwise, apply input validation/sanitization to all parameters processed by conf_mail.php, avoid passing user input to shell command execution, and restrict network access to the management interface.

Proof of Concept

Weakness (CWE)

CWE-78 OS Command Injection

EPSS Score

98%
Probability of exploitation in next 30 days
99.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE