CVE-2022-4257 is a critical argument injection vulnerability in the C-DATA Web Management System, specifically affecting the cgi-bin/jumpto.php component when handling the 'hostname' GET parameter. This flaw allows for remote exploitation, enabling attackers to inject arbitrary arguments. With a CVSS score of 9.8 (CRITICAL), it presents a high risk of complete compromise (confidentiality, integrity, availability). While no public exploit code is listed in common databases like Metasploit or ExploitDB, the vulnerability has been publicly disclosed, and its association with Mirai botnet variants suggests active targeting in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:cdatatec:c-data_web_management_system:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.