AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2022-31479

CRITICAL · CVSS 9.6 EPSS 2.44%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2022-06-06 · Last synced 2026-08-04

CyberRota Analysis

This is a critical severity vulnerability with a CVSS score of 9.6. It may be remotely exploitable. Exploitation may require the attacker to be authenticated.

CVE
CVE-2022-31479
Severity
CRITICAL
CVSS
9.6
EPSS
2.44%

Original NVD Description

An unauthenticated attacker can update the hostname with a specially crafted name that will allow for shell commands to be executed during the core collection process. This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 which contain firmware versions prior to 1.302 for the LP series and 1.296 for the EP series. An attacker with this level of access on the device can monitor all communications sent to and from this device, modify onboard relays, change configuration files, or cause the device to become unstable. The injected commands only get executed during start up or when unsafe calls regarding the hostname are used. This allows the attacker to gain remote access to the device and can make their persistence permanent by modifying the filesystem.

Related CVEs

Other vulnerabilities affecting the same vendor(s)