CRITICAL · 9.8

CVE-2022-42785

Multiple W&T products of the ComServer Series are prone to an authentication bypass. An unathenticated remote attacker, can log in without knowledge of the password by crafting a modified HTTP GET Req...

Vulnerability Description

Multiple W&T products of the ComServer Series are prone to an authentication bypass. An unathenticated remote attacker, can log in without knowledge of the password by crafting a modified HTTP GET Request.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
WutAt-Modem-Emulator Firmware< 1.48
WutAt-Modem-Emulator-
WutCom-Server \+\+ Firmware< 1.48
WutCom-Server \+\+-
WutCom-Server 20Ma Firmware< 1.48
WutCom-Server 20Ma-
WutCom-Server Highspeed 100Basefx Firmware< 1.76
WutCom-Server Highspeed 100Basefx-
WutCom-Server Highspeed 100Baselx Firmware< 1.76
WutCom-Server Highspeed 100Baselx-
WutCom-Server Highspeed 19\" 1Port Firmware< 1.76
WutCom-Server Highspeed 19\" 1Port-
WutCom-Server Highspeed 19\" 4Port Firmware< 1.76
WutCom-Server Highspeed 19\" 4Port-
WutCom-Server Highspeed Compact Firmware< 1.76
WutCom-Server Highspeed Compact-
WutCom-Server Highspeed Industry Firmware< 1.76
WutCom-Server Highspeed Industry-
WutCom-Server Highspeed Isolated Firmware< 1.76
WutCom-Server Highspeed Isolated-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-42785?

CVE-2022-42785 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Multiple W&T products of the ComServer Series are prone to an authentication bypass. An unathenticated remote attacker, can log in without knowledge of the password by crafting a modified HTTP GET Req...

How severe is CVE-2022-42785?

CVE-2022-42785 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2022-42785?

Check the references section above for vendor advisories and patch information. Affected products include: Wut At-Modem-Emulator Firmware, Wut At-Modem-Emulator, Wut Com-Server \+\+ Firmware, Wut Com-Server \+\+, Wut Com-Server 20Ma Firmware.