CVE-2022-30627 is a high-severity vulnerability (CVSS 7.5) affecting specific firmware versions of CHCNAV P5E GNSS products, allowing for the extraction of user and operating system passwords. This flaw, categorized as CWE-798 (Use of Hard-coded Credentials), can be exploited remotely over the network with low attack complexity and no user interaction, leading to a complete compromise of confidentiality. While the vulnerability poses a significant risk due to password exposure, there is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.1CPE matchmatch criteria | cpe:2.3:o:chcnav:p5e_gnss_firmware:4.1:*:*:*:*:*:*:* | ||
4.2CPE matchmatch criteria | cpe:2.3:o:chcnav:p5e_gnss_firmware:4.2:*:*:*:*:*:*:* | ||
update_b5_v2.0.9_b20200706CPE matchmatch criteria | cpe:2.3:o:chcnav:p5e_gnss_firmware:update_b5_v2.0.9_b20200706:*:*:*:*:*:*:* | ||
update_i50_v1.0.55_b20200509CPE matchmatch criteria | cpe:2.3:o:chcnav:p5e_gnss_firmware:update_i50_v1.0.55_b20200509:*:*:*:*:*:*:* | ||
update_i90_cv2.021_b20210104CPE matchmatch criteria | cpe:2.3:o:chcnav:p5e_gnss_firmware:update_i90_cv2.021_b20210104:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.