CVE-2022-31486
Estado: ModificadaAlta (8.8)—
An authenticated attacker can send a specially crafted route to the “edit_route.cgi” binary and have it execute shell commands. This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 which contain firmware versions prior to 1.303 for the LP series and 1.297 for the EP series. An attacker with this level of access on the device can monitor all communications sent to and from this device, modify onboard relays, change configuration files, or cause the device to become unstable.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 8.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.38%
- Percentil entre todas las CVEs puntuadas: 71
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (14)
Carrier — Lenels2 Lnl-4420 FirmwareCarrier — Lenels2 Lnl-x2210 FirmwareCarrier — Lenels2 Lnl-x2220 FirmwareCarrier — Lenels2 Lnl-x3300 FirmwareCarrier — Lenels2 Lnl-x4420 FirmwareCarrier — Lenels2 S2-lp-1501 FirmwareCarrier — Lenels2 S2-lp-1502 FirmwareCarrier — Lenels2 S2-lp-2500 FirmwareCarrier — Lenels2 S2-lp-4502 FirmwareHidglobal — Ep4502 FirmwareHidglobal — Lp1501 FirmwareHidglobal — Lp1502 FirmwareHidglobal — Lp2500 FirmwareHidglobal — Lp4502 Firmware
CWE
- CWE-78
- CWE-78
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-31486",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 9,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:C/I:C/A:C",
"authentication": "SINGLE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "productsecurity@carrier.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "productsecurity@carrier.com",
"affectedData": [
{
"vendor": "LenelS2",
"product": "LNL-X2210",
"versions": [
{
"status": "affected",
"version": "ALL",
"lessThan": "1.303",
"versionType": "custom"
}
]
},
{
"vendor": "LenelS2",
"product": "LNL-X2220",
"versions": [
{
"status": "affected",
"version": "ALL",
"lessThan": "1.303",
"versionType": "custom"
}
]
},
{
"vendor": "LenelS2",
"product": "LNL-X3300",
"versions": [
{
"status": "affected",
"version": "ALL",
"lessThan": "1.303",
"versionType": "custom"
}
]
},
{
"vendor": "LenelS2",
"product": "LNL-X4420",
"versions": [
{
"status": "affected",
"version": "ALL",
"lessThan": "1.303",
"versionType": "custom"
}
]
},
{
"vendor": "LenelS2",
"product": "LNL-4420",
"versions": [
{
"status": "affected",
"version": "ALL",
"lessThan": "1.297",
"versionType": "custom"
}
]
},
{
"vendor": "LenelS2",
"product": "S2-LP-1501",
"versions": [
{
"status": "affected",
"version": "ALL",
"lessThan": "1.303",
"versionType": "custom"
}
]
},
{
"vendor": "LenelS2",
"product": "S2-LP-1502",
"versions": [
{
"status": "affected",
"version": "ALL",
"lessThan": "1.303",
"versionType": "custom"
}
]
},
{
"vendor": "LenelS2",
"product": "S2-LP-2500",
"versions": [
{
"status": "affected",
"version": "ALL",
"lessThan": "1.303",
"versionType": "custom"
}
]
},
{
"vendor": "LenelS2",
"product": "S2-LP-4502",
"versions": [
{
"status": "affected",
"version": "ALL",
"lessThan": "1.303",
"versionType": "custom"
}
]
},
{
"vendor": "HID Mercury",
"product": "LP1501",
"versions": [
{
"status": "affected",
"version": "ALL",
"lessThan": "1.303",
"versionType": "custom"
}
]
},
{
"vendor": "HID Mercury",
"product": "LP1502",
"versions": [
{
"status": "affected",
"version": "ALL",
"lessThan": "1.303",
"versionType": "custom"
}
]
},
{
"vendor": "HID Mercury",
"product": "LP2500",
"versions": [
{
"status": "affected",
"version": "ALL",
"lessThan": "1.303",
"versionType": "custom"
}
]
},
{
"vendor": "HID Mercury",
"product": "LP4502",
"versions": [
{
"status": "affected",
"version": "ALL",
"lessThan": "1.303",
"versionType": "custom"
}
]
},
{
"vendor": "HID Mercury",
"product": "EP4502",
"versions": [
{
"status": "affected",
"version": "ALL",
"lessThan": "1.297",
"versionType": "custom"
}
]
}
]
}
],
"published": "2022-06-06T17:15:11.810",
"references": [
{
"url": "https://www.corporate.carrier.com/product-security/advisories-resources/",
"tags": [
"Vendor Advisory"
],
"source": "productsecurity@carrier.com"
},
{
"url": "https://www.corporate.carrier.com/product-security/advisories-resources/",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "productsecurity@carrier.com",
"description": [
{
"lang": "en",
"value": "CWE-78"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-78"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An authenticated attacker can send a specially crafted route to the “edit_route.cgi” binary and have it execute shell commands. This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 which contain firmware versions prior to 1.303 for the LP series and 1.297 for the EP series. An attacker with this level of access on the device can monitor all communications sent to and from this device, modify onboard relays, change configuration files, or cause the device to become unstable."
},
{
"lang": "es",
"value": "Un atacante autenticado puede enviar una ruta especialmente diseñada al binario \"edit_route.cgi\" y hacer que ejecute comandos de shell. Esta vulnerabilidad afecta a los productos basados en los controladores inteligentes HID Mercury LP1501, LP1502, LP2500, LP4502 y EP4502 que contienen versiones de firmware anteriores a 1.303 para la serie LP y 1.297 para la serie EP. Un atacante con este nivel de acceso en el dispositivo puede monitorear todas las comunicaciones enviadas hacia y desde este dispositivo, modificar los relés incorporados, cambiar los archivos de configuración o causar que el dispositivo se vuelva inestable"
}
],
"lastModified": "2026-06-17T04:45:32.700",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:hidglobal:lp1501_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B8EB5D8F-0EAF-4960-9C1F-4E43614AEF1E",
"versionEndExcluding": "1.303"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:hidglobal:lp1501:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "B9DC3EC5-C67D-4FE5-8B53-04AB785588FE"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:hidglobal:lp1502_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B2753AA2-75FC-40F7-A8EC-D76CB3BAEC9C",
"versionEndExcluding": "1.303"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:hidglobal:lp1502:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "902FDABA-C5D0-4CAE-BBDF-E4338D3A4DAF"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:hidglobal:lp2500_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CB0D54B1-6140-4BD5-A49D-B5983A2CCB84",
"versionEndExcluding": "1.303"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:hidglobal:lp2500:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "AAC2A69E-BF7D-448B-8347-19CFFABED15A"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:hidglobal:lp4502_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7F351A13-995A-43C0-A87D-B534DCD8512E",
"versionEndExcluding": "1.303"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:hidglobal:lp4502:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "22147A65-6ADE-46F3-AFF8-E46CE81D6E8B"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:hidglobal:ep4502_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6F16DD76-4C6B-4ACE-BFAB-C6FCA6355BB5",
"versionEndExcluding": "1.297"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:hidglobal:ep4502:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "F9A28A38-C57D-4FC6-8CAA-0011AF06D290"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carrier:lenels2_lnl-4420_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3862AEE4-5B50-434E-B293-3322F6AAE5FE",
"versionEndExcluding": "1.297"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:carrier:lenels2_lnl-4420:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "36855319-E36B-47C3-B27E-E1509D1C9D4D"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carrier:lenels2_lnl-x2210_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2424FA8C-D7D5-40BD-8510-9F1A20C4ADD4",
"versionEndExcluding": "1.303"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:carrier:lenels2_lnl-x2210:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "3B091C8F-2C3A-47C9-92AC-550D977F781A"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carrier:lenels2_lnl-x2220_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "854B319F-2138-4F18-96CA-73B13927A4D8",
"versionEndExcluding": "1.303"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:carrier:lenels2_lnl-x2220:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "15FD8460-39D0-46C4-9F04-EB3B6C72767A"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carrier:lenels2_lnl-x3300_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6C2395B5-E7CC-4A9E-99AB-617D5541B84E",
"versionEndExcluding": "1.303"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:carrier:lenels2_lnl-x3300:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "389BE7A1-1B57-4097-9AAF-A6931C06BA15"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carrier:lenels2_lnl-x4420_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "531D12F9-E636-43C5-8E66-CA057DAFC4BF",
"versionEndExcluding": "1.303"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:carrier:lenels2_lnl-x4420:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "2BC2BAEA-E139-47C2-9A8F-857AB1C7D54B"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carrier:lenels2_s2-lp-1501_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3EF4C948-4174-4F5A-881B-0FB985D9331D",
"versionEndExcluding": "1.303"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:carrier:lenels2_s2-lp-1501:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "3183C665-CD31-446D-8D95-908148675D25"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carrier:lenels2_s2-lp-1502_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0722187B-9BCB-4D59-9E47-10700F331AEE",
"versionEndExcluding": "1.303"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:carrier:lenels2_s2-lp-1502:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "93B38941-79D8-41E7-9763-989C0C3B6139"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carrier:lenels2_s2-lp-2500_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7322CD14-B238-44B8-A3F6-C2FD91EEADBC",
"versionEndExcluding": "1.303"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:carrier:lenels2_s2-lp-2500:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "1724D78F-EE79-4E48-BDB2-D399C573F42D"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:carrier:lenels2_s2-lp-4502_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EF3856F1-9777-4389-A8B5-228EE3858C89",
"versionEndExcluding": "1.303"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:carrier:lenels2_s2-lp-4502:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "115129D2-5134-4BCD-B5D0-263F4687B59D"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "productsecurity@carrier.com"
}