CVE-2022-24796 is a critical Remote Code Execution (RCE) vulnerability affecting RaspberryMatic, an open-source operating system for smart-home devices, specifically versions prior to 3.63.8.20220330. The flaw resides in the WebUI's file upload facility, where missing input validation allows unauthenticated attackers to execute arbitrary operating system commands as root via shell metacharacters in HTTP query strings. This vulnerability carries a CVSS score of 9.8 (Critical) due to its network-based attack vector, low attack complexity, and complete compromise potential (Confidentiality, Integrity, Availability). There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion, and it is not listed in the CISA KEV catalog. Users are strongly advised to update to version 3.63.8.20220330 or newer as no workarounds exist.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.31.25.20180428, < 3.63.8.20220330CPE matchmatch criteria | cpe:2.3:o:raspberrymatic:raspberrymatic:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.