8.8
CVSSv3

CVE-2022-34753

Published: 13/07/2022 Updated: 27/07/2022
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote root exploit when the command is compromised. Affected Products: SpaceLogic C-Bus Home Controller (5200WHC2), formerly known as C-Bus Wiser Homer Controller MK2 (V1.31.460 and prior)

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

schneider-electric spacelogic_c-bus_home_controller_firmware

Exploits

Schneider Electric SpaceLogic C-Bus Home Controller (5200WHC2) versions 131460 and below suffer from an authenticated OS command injection vulnerability This can be exploited to inject and execute arbitrary shell commands as the root user via the name GET parameter in delsnappl Perl/CGI script which is used for deleting snapshots taken from the ...

Github Repositories

A PoC exploit for CVE-2022-34753 - OS Command Injection in SpaceLogic C-Bus Home Controller

CVE-2022-34753 - OS Command Injection in SpaceLogic C-Bus Home Controller CVE-2022-34753 is a critical security vulnerability classified under CWE-78, indicating an "Improper Neutralization of Special Elements used in an OS Command" (commonly referred to as 'OS Command Injection') This vulnerability poses a significant risk as it may lead to a remote root e