CVE-2022-47732 is a critical vulnerability affecting Yeastar N412 and N824 Configuration Panels (versions 42.x and 45.x). An unauthenticated attacker can exploit this flaw to create and download a backup file, which contains the administrator hash. This allows for potential password cracking or replacement of the hash within the backup to gain unauthorized administrative access to the device. With a CVSS score of 7.5 (High), this vulnerability has a low attack complexity and requires no user interaction, posing a significant risk of complete compromise. There is currently no public exploit code available, nor is there evidence of active exploitation or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:yeastar:n824_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:yeastar:n412_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.