CVE-2022-46304 HIGH

CVE-2022-46304: ChangingTec ServiSign - Command Injection

Weakness CWE-78
Published January 3, 2023
Last update April 10, 2025

CVSS base score

8.8/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

ChangingTec ServiSign component has insufficient filtering for special characters in the connection response parameter. An unauthenticated remote attacker can host a malicious website for the component user to access, which triggers command injection and allows the attacker to execute arbitrary system command to perform arbitrary system operation or disrupt service.

Key dates

02Disclosure timeline

January 3, 2023 CVE published
April 10, 2025 Record updated