CVE-2022-44149EPSS p99.1%
CVE-2022-44149CVE-2022-44149
nexxtsolutions / amp300_firmware
Description
The web service on Nexxt Amp300 ARN02304U8 42.103.1.5095 and 80.103.2.5045 devices allows remote OS command execution by placing &telnetd in the JSON host field to the ping feature of the goform/sysTools component. Authentication is required
Scoring
| CVSS | 8.8 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 64.35% probability of exploitation · percentile 99.1% · 2026-06-18T12:00:27Z |
| Last modified | 2026-06-17 |