← Vulnerability feed

Vulnerability record · CVE-2022-45711 · published 23 December 2022

CVE-2022-45711: Ip-com m50 firmware os command injection vulnerability

IIp Com · M50 Firmware

IP-COM M50 V15.11.0.33(10768) was discovered to contain a command injection vulnerability via the hostname parameter in the formSetNetCheckTools function.

9.8 CVSS 3.1 Critical EPSS 20% · top 2.6% CWE-78 · OS command injection
9.8CVSS 3.1 base score
20%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References, 3 tagged exploit
17 Jun 2026Last modified by NVD

Description

IP-COM M50 V15.11.0.33(10768) was discovered to contain a command injection vulnerability via the hostname parameter in the formSetNetCheckTools function.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://hackmd.io/dLM8vDnwQOup8mmDbHJRHQ?both ExploitThird Party Advisory
https://hackmd.io/dLM8vDnwQOup8mmDbHJRHQ?both ExploitThird Party Advisory
https://hackmd.io/dLM8vDnwQOup8mmDbHJRHQ?both ExploitThird Party Advisory

Track CVE-2022-45711 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-45715Ip-com m50 firmware classic buffer overflow vulnerabilityIP-COM M50 V15.11.0.33(10768) was discovered to contain multiple buffer overflows via the pLanPortRange and pWanPortRange parameters in the formSetPo…EPSS 1.1%9.8CVE-2022-45716Ip-com m50 firmware classic buffer overflow vulnerabilityIP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the indexSet parameter in the formIPMacBindDel function.EPSS 1.1%9.8CVE-2022-45717Ip-com m50 firmware os command injection vulnerabilityIP-COM M50 V15.11.0.33(10768) was discovered to contain a command injection vulnerability via the usbPartitionName parameter in the formSetUSBPartiti…EPSS 4.3%9.8CVE-2022-45718Ip-com m50 firmware classic buffer overflow vulnerabilityIP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the rules parameter in the formIPMacBindAdd function.EPSS 1.1%9.8CVE-2022-45719Ip-com m50 firmware classic buffer overflow vulnerabilityIP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the gotoUrl parameter in the formPortalAuth function.EPSS 1.1%9.8CVE-2022-45720Ip-com m50 firmware classic buffer overflow vulnerabilityIP-COM M50 V15.11.0.33(10768) was discovered to contain multiple buffer overflows via the ip, mac, and remark parameters in the formIPMacBindModify f…EPSS 1.1%9.8CVE-2022-45721Ip-com m50 firmware classic buffer overflow vulnerabilityIP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the picName parameter in the formDelWewifiPic function.EPSS 1.1%9.8CVE-2022-45706Ip-com m50 firmware classic buffer overflow vulnerabilityIP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the hostname parameter in the formSetNetCheckTools function.EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2022-45711), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.