Junglewise Threat Intelligence

CVE-2022-29303: SolarView Compact Command Injection Vulnerability

CVE-2022-29303 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2023-07-13

Vendors: Contec.

Executive brief

SolarView Compact contains an OS command injection vulnerability in the conf_mail.php component. The flaw arises from improper validation of input values on the send test mail console, allowing unauthenticated remote attackers to execute arbitrary commands.

Affected products

  • Contec SolarView Compact SV-CPT-MC310 Firmware 6.00

Timeline

  • 2022-05-12: disclosed: NVD Published Date
  • 2023-07-13: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-08-03: other: CISA Due Date for remediation