CVE-2022-24630 Information

Description

An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. BrowseFiles.php allows a ?cmd=ssh POST request with an ssh_command field that is executed.

Reference

http://seclists.org/fulldisclosure/2023/Feb/12

Share on: