CVE-2022-1509 is a critical command injection vulnerability affecting Hestia Control Panel versions prior to 1.5.12, allowing authenticated low-privilege attackers to execute arbitrary code with root privileges. This vulnerability carries a high CVSS score of 8.8, indicating a severe risk due to its network-based attack vector and complete compromise potential for confidentiality, integrity, and availability. While there is no evidence of active exploitation (KEV listed as No) and no public exploit code (Metasploit, Nuclei, ExploitDB are empty), the vulnerability has garnered significant community discussion, suggesting awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.5.12CPE matchmatch criteria | cpe:2.3:a:hestiacp:control_panel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.