8.8
CVSSv3

CVE-2022-23332

Published: 09/05/2022 Updated: 08/08/2023
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 801
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

Command injection vulnerability in Manual Ping Form (Web UI) in Shenzhen Ejoin Information Technology Co., Ltd. ACOM508/ACOM516/ACOM532 609-915-041-100-020 allows a remote malicious user to inject arbitrary code via the field.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ejointech acom508 firmware

ejointech acom532 firmware

ejointech acom516 firmware -

Github Repositories

Common Vulnerabilities and Exposures Report Researcher : Kyle Song CVE-2022-23332 Ejoin Technology VoIP Gateway (ACOM Series) - Command Injection Vulnerability (RCE)