SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-45291

PWS Personal Weather Station Dashboard (PWS_Dashboard) LTS December 2020 (2012_lts) allows remote code execution by injecting PHP code into settings.php.

HIGH 7.2EPSS 1.33%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.33%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

PWS Personal Weather Station Dashboard (PWS_Dashboard) LTS December 2020 (2012_lts) allows remote code execution by injecting PHP code into settings.php. Attacks can use the PWS_printfile.php, PWS_frame_text.php, PWS_listfile.php, PWS_winter.php, and PWS_easyweathersetup.php endpoints. A contributing factor is a hardcoded login password of support, which is not documented. (This is not the same as the documented setup password, which is 12345.) The issue was fixed in late 2022.

CVSS 3.1
7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
1.33% probability · 69th percentile
CISA KEV
Not listed
Weakness
CWE-798
Affected
pwsdashboard/personal weather station dashboard
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.