CVE-2022-44038

Russound XSourcePlayer 777D v06.08.03 was discovered to contain a remote code execution vulnerability via the scriptRunner.cgi component.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:russound:xsourceplayer_777d_firmware:06.08.03:*:*:*:*:*:*:*
cpe:2.3:h:russound:xsourceplayer_777d:-:*:*:*:*:*:*:*

History

25 Apr 2025, 16:15

Type Values Removed Values Added
CWE CWE-94

21 Nov 2024, 07:27

Type Values Removed Values Added
References () https://cyber-guy.gitbook.io/cyber-guys-blog/pocs/cve-2022-44038 - Exploit, Third Party Advisory () https://cyber-guy.gitbook.io/cyber-guys-blog/pocs/cve-2022-44038 - Exploit, Third Party Advisory

Information

Published : 2022-11-29 04:15

Updated : 2025-04-25 16:15


NVD link : CVE-2022-44038

Mitre link : CVE-2022-44038

CVE.ORG link : CVE-2022-44038


JSON object : View

Products Affected

russound

  • xsourceplayer_777d
  • xsourceplayer_777d_firmware
CWE
NVD-CWE-noinfo CWE-94

Improper Control of Generation of Code ('Code Injection')