CVE-2022-33948
Estado: ModificadaAlta (8.8)—
HOME SPOT CUBE2 V102 contains an OS command injection vulnerability due to improper processing of data received from DHCP server. An adjacent attacker may execute an arbitrary OS command on the product if a malicious DHCP server is placed on the WAN side of the product.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 8.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.91%
- Percentil entre todas las CVEs puntuadas: 59
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-78
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-33948",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 8.3,
"accessVector": "ADJACENT_NETWORK",
"vectorString": "AV:A/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 6.5,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "vultures@jpcert.or.jp",
"affectedData": [
{
"vendor": "KDDI CORPORATION",
"product": "HOME SPOT CUBE2",
"versions": [
{
"status": "affected",
"version": "V102 and earlier"
}
]
}
]
}
],
"published": "2022-07-04T02:15:07.620",
"references": [
{
"url": "https://jvn.jp/en/jp/JVN41017328/index.html",
"tags": [
"Third Party Advisory"
],
"source": "vultures@jpcert.or.jp"
},
{
"url": "https://www.au.com/support/service/mobile/guide/wlan/home_spot_cube_2/",
"tags": [
"Product",
"Vendor Advisory"
],
"source": "vultures@jpcert.or.jp"
},
{
"url": "https://jvn.jp/en/jp/JVN41017328/index.html",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.au.com/support/service/mobile/guide/wlan/home_spot_cube_2/",
"tags": [
"Product",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-78"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "HOME SPOT CUBE2 V102 contains an OS command injection vulnerability due to improper processing of data received from DHCP server. An adjacent attacker may execute an arbitrary OS command on the product if a malicious DHCP server is placed on the WAN side of the product."
},
{
"lang": "es",
"value": "HOME SPOT CUBE2 versión V102, contiene una vulnerabilidad de inyección de comandos del Sistema Operativo debido a un procesamiento inapropiado de datos recibidos del servidor DHCP. Un atacante adyacente puede ejecutar un comando de Sistema Operativo arbitrario en el producto si es colocado un servidor DHCP malicioso en el lado WAN del producto"
}
],
"lastModified": "2026-06-17T04:49:32.373",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:kddi:home_spot_cube_2_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E698D6BB-9235-4361-8BD5-F3338A09B119",
"versionEndIncluding": "v102"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:kddi:home_spot_cube_2:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "330A6D16-3BBA-4D46-B7C1-17C08C8373D5"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "vultures@jpcert.or.jp"
}