CVE-2022-23770 HIGH

CVE-2022-23770: WISA Smart Wing CMS Remote Command Execution Vulnerability

Vendor Wisa Corp.
Product Smart Wing CMS
Weakness CWE-20 · Input validation
Published October 17, 2022
Last update May 13, 2025

CVSS base score

8.8/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

This vulnerability could allow a remote attacker to execute remote commands with improper validation of parameters of certain API constructors. Remote attackers could use this vulnerability to execute malicious commands such as directory traversal.

Key dates

02Disclosure timeline

October 17, 2022 CVE published
May 13, 2025 Record updated