CVE-2022-2634 is a critical vulnerability affecting Digi ConnectPort X2D devices and their firmware, stemming from insufficient device access protections and permissions within the web application. This flaw allows an unauthenticated attacker to remotely execute arbitrary Python files, leading to complete compromise of the device. With a CVSS score of 9.8 (CRITICAL), the vulnerability is easily exploitable over the network with no user interaction required, resulting in high impact to confidentiality, integrity, and availability. While not currently listed in CISA's KEV catalog and lacking public exploit intelligence like Metasploit or ExploitDB, the vulnerability has garnered significant community discussion, indicating awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2020-01-01CPE matchmatch criteria | cpe:2.3:o:digi:connectport_x2d_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.