CVE-2022-24629
60Vexday Risk Score
Keep watching. It has a public proof of concept.
ssvc Attendcvss 9.8epss 37%
from disclosure to weapon0 days
Published on NVDMay 29
1st PoCMar 30
exploitation probability
37%top 2% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. Remote code execution can be achieved via directory traversal in the dir parameter of the file upload functionality of BrowseFiles.php. An attacker can upload a .php file to WebAdmin/admin/AudioCodes_files/ajax/.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/apublic PoCs found — 1
exploitdbwww.exploit-db.com/exploits/51145unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.