CVE-2022-4982 is a local file inclusion vulnerability affecting DBLTek GoIP-1 firmware versions up to GHSFVT-1.1-67-5, with other GoIP models likely also impacted. The vulnerability allows an unauthenticated attacker to read arbitrary files from the device's filesystem due to improper validation of the 'content' or 'sidebar' parameters in web server handlers. This flaw carries a high CVSSv4 score of 8.7, indicating a critical risk with network-based exploitation and high confidentiality impact. While exploitation evidence was observed by the Shadowserver Foundation in March 2024, there is currently no public exploit code available, and the vulnerability has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| DBL Technology (DBLTek) | GoIP-1 | >= 0, <= GHSFVT-1.1-67-5CNA affecteddefault unknown |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.