CVE-2022-29337 is a critical command injection vulnerability in C-DATA FD702XW-X-R430 v2.1.13_X001 firmware, allowing unauthenticated attackers to execute arbitrary commands via a crafted HTTP request to the formlanipv6 parameter. With a CVSS score of 9.8, this vulnerability poses a severe risk, enabling complete compromise of confidentiality, integrity, and availability without user interaction. Despite its high severity and a FAUCET Risk Score of 96/100, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage. This suggests it is not currently a widely targeted threat, though the potential impact remains high.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.1.13_x001CPE matchmatch criteria | cpe:2.3:o:cdatatec:fd702xw-x-r430_firmware:2.1.13_x001:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.