CVE Feed

    Dashboard / CVE / CVE-2022-45291

    CVE-2022-45291

    PWS Personal Weather Station Dashboard (PWS_Dashboard) LTS December 2020 (2012_lts) allows remote code execution by injecting PHP code into settings.php. Attacks can use the PWS_printfile.php, PWS_frame_text.php, PWS_listfile.php, PWS_winter.php, and PWS_easyweathersetup.php endpoints. A contributing factor is a hardcoded login password of support, which is not documented. (This is not the same as the documented setup password, which is 12345.) The issue was fixed in late 2022.

    Published:Apr 25, 2023
    Last Modified:Feb 4, 2025
    EPS:Apr 25, 2023
    EPSS Score:0.01025
    CVSS Score:7.2

    Affected Products

    Vendor
    Pwsdashboard
    Product
    Personal Weather Station Dashboard

    Common Weakness Enumeration

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High