{"advisories":[{"id":"EUVD-2022-37491","source":"euvd","title":"Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a command injection vulnerability in the component /admin/vca/bia/addacph.cgi. This vulnerability is exploitable via a crafted POST request.","url":"https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-37491"}],"cve":"CVE-2022-34538","epss":{"score":0.02727},"mitre":{"cpes":[],"created":"2022-07-19T19:03:57+00:00","description":"Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a command injection vulnerability in the component /admin/vca/bia/addacph.cgi. This vulnerability is exploitable via a crafted POST request.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{}},"mitre_repo_path":"cves/2022/34xxx/CVE-2022-34538.json","references":["https://gist.github.com/secgrant/820faeeaa0cb4889edaa1d6fef83deab"],"title":null,"updated":"2024-08-03T09:15:15.150000+00:00","vendors":[],"weaknesses":[]},"nvd":{"cpes":["cpe:2.3:h:dw:megapix:-:*:*:*:*:*:*:*","cpe:2.3:o:dw:megapix_firmware:4.2.0.32842:*:*:*:*:*:*:*"],"created":"2022-07-19T20:15:11.627000+00:00","description":"Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a command injection vulnerability in the component /admin/vca/bia/addacph.cgi. This vulnerability is exploitable via a crafted POST request.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":8.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"cvssV4_0":{}},"nvd_repo_path":"2022/CVE-2022-34538.json","references":["https://gist.github.com/secgrant/820faeeaa0cb4889edaa1d6fef83deab"],"title":null,"updated":"2026-06-17T04:50:29.717000+00:00","vendors":["dw","dw$PRODUCT$megapix","dw$PRODUCT$megapix_firmware"],"weaknesses":["CWE-78"]},"opencve":{"changes":[],"cpes":{"data":["cpe:2.3:h:dw:megapix:-:*:*:*:*:*:*:*","cpe:2.3:o:dw:megapix_firmware:4.2.0.32842:*:*:*:*:*:*:*"],"providers":["nvd"]},"created":{"data":"2022-07-19T19:03:57+00:00","provider":"mitre"},"description":{"data":"Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a command injection vulnerability in the component /admin/vca/bia/addacph.cgi. This vulnerability is exploitable via a crafted POST request.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{},"provider":null},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{"score":8.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"provider":"nvd"},"cvssV4_0":{"data":{},"provider":null},"epss":{"data":{"score":0.02727},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{},"provider":null},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://gist.github.com/secgrant/820faeeaa0cb4889edaa1d6fef83deab"],"providers":["mitre","nvd"]},"title":{"data":null,"provider":null},"updated":{"data":"2024-11-21T07:09:43.727000+00:00","provider":"nvd"},"vendors":{"data":["dw","dw$PRODUCT$megapix","dw$PRODUCT$megapix_firmware"],"providers":["nvd"]},"weaknesses":{"data":["CWE-78"],"providers":["nvd"]}}}