CVE-2022-29516 is a critical vulnerability affecting the web console of multiple FUJITSU Network IPCOM series products, including various models within the EX2 and EX lines. This flaw allows a remote, unauthenticated attacker to execute arbitrary operating system commands due to an unspecified vulnerability (CWE-78). With a CVSS score of 9.8, this vulnerability poses a severe risk, enabling complete compromise of confidentiality, integrity, and availability. While no public exploits, Metasploit modules, or Nuclei templates are currently available, and there is no evidence of active exploitation or significant community discussion, the high severity warrants immediate attention and patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< v01l05_nf0501CPE matchmatch criteria | cpe:2.3:o:fujitsu:ipcom_ex2_nw_1100_firmware:*:*:*:*:*:*:*:* | ||
< v01l05_nf0501CPE matchmatch criteria | cpe:2.3:o:fujitsu:ipcom_ex2_nw_3500_firmware:*:*:*:*:*:*:*:* | ||
< v01l05_nf0501CPE matchmatch criteria | cpe:2.3:o:fujitsu:ipcom_ex2_nw_3200_firmware:*:*:*:*:*:*:*:* | ||
< v01l05_nf0501CPE matchmatch criteria | cpe:2.3:o:fujitsu:ipcom_ex2_sc_1100_firmware:*:*:*:*:*:*:*:* | ||
< v01l05_nf0501CPE matchmatch criteria | cpe:2.3:o:fujitsu:ipcom_ex2_sc_3500_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.