CVE-2022-31479 is a critical remote code execution vulnerability affecting HID Mercury Intelligent Controllers (LP and EP series) with outdated firmware. An unauthenticated attacker can inject shell commands by crafting a malicious hostname, which are executed during core collection or startup. This allows for full compromise of the device, including monitoring communications, modifying relays, and achieving persistent remote access. Rated 9.8 CVSS (Critical), the vulnerability is easily exploitable over the network with low attack complexity and no user interaction required. While no public exploit code is currently available, the vulnerability has garnered significant community discussion and media attention, indicating a high level of interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.302CPE matchmatch criteria | cpe:2.3:o:hidglobal:lp1501_firmware:*:*:*:*:*:*:*:* | ||
< 1.302CPE matchmatch criteria | cpe:2.3:o:hidglobal:lp1502_firmware:*:*:*:*:*:*:*:* | ||
< 1.302CPE matchmatch criteria | cpe:2.3:o:hidglobal:lp2500_firmware:*:*:*:*:*:*:*:* | ||
< 1.302CPE matchmatch criteria | cpe:2.3:o:hidglobal:lp4502_firmware:*:*:*:*:*:*:*:* | ||
< 1.296CPE matchmatch criteria | cpe:2.3:o:hidglobal:ep4502_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.