setPasswordCfg of the component Request Handler. The manipulation of the argument adminuser/adminpass leads to command injection.
This vulnerability was named CVE-2022-28496. Access to the local network is required for this attack. There is no exploit available.
Intelligence View
SOCIAL SHARE CARD GENERATOR