Back

HIGH

The web server of Hirschmann BAT-C2 before 09.13.01.00R04 allows authenticated command injection

Published Nov 25, 2022

Description

The web server of Hirschmann BAT-C2 before 09.13.01.00R04 allows authenticated command injection. This allows an authenticated attacker to pass commands to the shell of the system because the dir parameter of the FsCreateDir Ajax function is not sufficiently sanitized. The vendor's ID is BSECV-2022-21.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 25, 2022
Updated Apr 29, 2025
Reserved Sep 8, 2022
CISA Vulnrichment
Updated Apr 29, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a