Vulnerability record · CVE-2022-45699 · published 10 February 2023
CVE-2022-45699: APSystems ECU-R admin interface command injection via timezone parameter
Apsystems · Ecu R Firmware
The administration interface of APSystems ECU-R firmware version 5203 passes the timezone parameter to a system command without sanitization, allowing OS command injection. A remote attacker can execute arbitrary commands as root without authentication, making this a critical flaw for exposed devices.
Description
Command injection in the administration interface in APSystems ECU-R version 5203 allows a remote unauthenticated attacker to execute arbitrary commands as root using the timezone parameter.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required, root-level impact, and public exploit code with very high EPSS make this an urgent fix for any exposed ECU-R device.
What it is
The administration interface of APSystems ECU-R firmware version 5203 passes the timezone parameter to a system command without sanitization, allowing OS command injection. A remote attacker can execute arbitrary commands as root without authentication, making this a critical flaw for exposed devices.
Impact
An attacker gains root-level command execution on the ECU-R device, enabling full control of the unit, data exfiltration, or use as a network pivot. Because the device is an energy communication unit, compromise can also affect monitoring and control of connected solar equipment.
Attack surface
The flaw is reachable over the network through the administration interface (AV:N, PR:N, UI:N). No authentication or user interaction is required, so any host that can reach the interface can attempt exploitation.
Exploitation
Public exploit code and a demonstration video are referenced, and EPSS is 0.766 (99.5th percentile), indicating high likelihood of exploitation. The CVE is not listed in CISA KEV, so no confirmed in-the-wild activity is recorded in this dataset.
What to do
- Apply the vendor firmware update for APSystems ECU-R that addresses the timezone parameter command injection; if no fixed version is available, isolate the device.
- Remove ECU-R administration interfaces from direct internet exposure and place them behind a firewall or VPN.
- Restrict management access to trusted internal networks and disable remote administration where not required.
- Monitor vendor advisories for ECU-R firmware updates and verify the installed version is not 5203 or otherwise vulnerable.
- If the device cannot be patched or isolated, power it down or replace it with a supported model.
Detection
- Inspect HTTP requests to the ECU-R administration interface for timezone parameters containing shell metacharacters such as ;, |, $(), or backticks.
- Monitor device or network logs for unexpected outbound connections or command execution behavior originating from the ECU-R.
- Use network monitoring to alert on access to the ECU-R admin interface from untrusted or external IP addresses.
- Check ECU-R firmware version and compare against vendor-patched releases.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/0xst4n/APSystems-ECU-R-RCE-Timezone | ExploitThird Party Advisory |
| https://web.archive.org/web/20230626075954/https://github.com/0xst4n/APSystems-ECU-R-RCE-Timezone | |
| https://www.youtube.com/watch?v=YNeeaDPJOBY | Exploit |
| https://github.com/0xst4n/APSystems-ECU-R-RCE-Timezone | ExploitThird Party Advisory |
| https://www.youtube.com/watch?v=YNeeaDPJOBY | Exploit |
Track CVE-2022-45699 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-45699), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.