Elsight – Elsight Halo  Remote Code Execution (RCE)
Elsight Halo web panel allows us to perform connection validation.
through the POST request :
/api/v1/nics/wifi/wlan0/ping
we can abuse DESTINATION parameter and leverage it to remote code execution.

Fixes

Solution

Update to version 10.6.1


Workaround

No workaround given by the vendor.

History

Fri, 25 Apr 2025 21:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCD

Published:

Updated: 2025-04-25T20:15:24.502Z

Reserved: 2022-07-26T00:00:00.000Z

Link: CVE-2022-36784

cve-icon Vulnrichment

Updated: 2024-08-03T10:14:28.444Z

cve-icon NVD

Status : Modified

Published: 2022-11-17T23:15:16.317

Modified: 2025-04-25T21:15:32.567

Link: CVE-2022-36784

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.