CVE-2022-46169

Cacti Command Injection Vulnerability

9.8
CVSS 3.1
99.8 %
EPSS (current)
2023-02-16
KEV addition
No
Ransomware

Timeline

Publication, first public exploit and KEV addition on a day axis.

Key facts

Vendor / product: Cacti / Cacti

Published: 2022-12-05 · Due (CISA): 2023-03-09

CWE: CWE-78 · EU list: no

Exploit references (metadata only)

SourceReferenceTitleDate
nucleihttp/cves/2022/CVE-2022-46169.yamlCacti <=1.2.22 - Remote Command Injection–
metasploitexploit/linux/http/cacti_unauthenticated_cmd_injectionexploit/linux/http/cacti_unauthenticated_cmd_injection2022-12-05
exploitdb51166Cacti v1.2.22 - Remote Command Execution (RCE)2023-03-31

References only — no downloads or instructions.

Sources