CVE-2022-26131 describes a critical vulnerability in Hegemon Electronics PLC4TRUCKS J2497 trailer receivers, allowing remote radio frequency (RF) induced signals to compromise the system. With a CVSS score of 9.8 (CRITICAL), this vulnerability can be exploited remotely without authentication or user interaction, leading to complete compromise of confidentiality, integrity, and availability. While there is no known active exploitation, public exploit code, or KEV listing, the vulnerability has garnered significant community discussion and media coverage, indicating awareness of its potential impact. The low EPSS score suggests a low probability of exploitation in the wild despite its high severity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
j2497CPE matchmatch criteria | cpe:2.3:o:hegemonelectronics:plc4trucks_firmware:j2497:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.