CVE-2022-35733

Missing authentication for critical function vulnerability in UNIMO Technology digital video recorders (UDR-JA1004/JA1008/JA1016 firmware versions v1.0.20.13 and earlier, and UDR-JA1016 firmware versions v2.0.20.13 and earlier) allows a remote unauthenticated attacker to execute an arbitrary OS command by sending a specially crafted request to the affected device web interface.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:unimo:udr-ja1004_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:unimo:udr-ja1004:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:unimo:udr-ja1008_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:unimo:udr-ja1008:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:unimo:udr-ja1016_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:unimo:udr-ja1016:-:*:*:*:*:*:*:*

History

21 Nov 2024, 07:11

Type Values Removed Values Added
References () http://www.unimo.co.jp/table_notice/index.php?act=1&resid=1643590226-637355 - Vendor Advisory () http://www.unimo.co.jp/table_notice/index.php?act=1&resid=1643590226-637355 - Vendor Advisory
References () https://jvn.jp/en/vu/JVNVU90821877/index.html - Third Party Advisory () https://jvn.jp/en/vu/JVNVU90821877/index.html - Third Party Advisory

Information

Published : 2022-08-23 02:15

Updated : 2024-11-21 07:11


NVD link : CVE-2022-35733

Mitre link : CVE-2022-35733

CVE.ORG link : CVE-2022-35733


JSON object : View

Products Affected

unimo

  • udr-ja1008_firmware
  • udr-ja1008
  • udr-ja1016_firmware
  • udr-ja1016
  • udr-ja1004
  • udr-ja1004_firmware
CWE
CWE-306

Missing Authentication for Critical Function