Command injection vulnerability in Manual Ping Form (Web UI) in Shenzhen Ejoin Information Technology Co., Ltd. ACOM508/ACOM516/ACOM532 609-915-041-100-020 allows a remote attacker to inject arbitrary code via the field.
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Link | Tags |
---|---|
http://en.ejointech.com/ | vendor advisory |
https://drive.google.com/drive/folders/1QRs6wos3mL9289TTUm98n5OmgBVrbYTx | third party advisory exploit |
https://github.com/kyl3song/CVE/tree/main/CVE-2022-23332 | third party advisory exploit |