Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2022-27632

8.8 · HIGH
Published May 18, 2022 meikyo CWE-352 EPSS 0.52% (42th pctl)

Overview

CVE-2022-27632 is a high-severity vulnerability affecting meikyo watch_boot_nino_rpc-m2c_firmware. It was published on May 18, 2022 and has a CVSS 3.1 base score of 8.8 (HIGH).

This vulnerability has a CVSS 3.1 base score of 8.8, rated HIGH. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.

Technical Description

Cross-site request forgery (CSRF) vulnerability in Rebooter(WATCH BOOT nino RPC-M2C [End of Sale] all firmware versions, WATCH BOOT light RPC-M5C [End of Sale] all firmware versions, WATCH BOOT L-zero RPC-M4L [End of Sale] all firmware versions, WATCH BOOT mini RPC-M4H [End of Sale] all firmware versions, WATCH BOOT nino RPC-M2CS firmware version 1.00A to 1.00D, WATCH BOOT light RPC-M5CS firmware version 1.00A to 1.00D, WATCH BOOT L-zero RPC-M4LS firmware version 1.00A to 1.20A, and Signage Rebooter RPC-M4HSi firmware version 1.00A), PoE Rebooter(PoE BOOT nino PoE8M2 firmware version 1.00A to 1.20A), Scheduler(TIME BOOT mini RSC-MT4H [End of Sale] all firmware versions, TIME BOOT RSC-MT8F [End of Sale] all firmware versions, TIME BOOT RSC-MT8FP [End of Sale] all firmware versions, TIME BOOT mini RSC-MT4HS firmware version 1.00A to 1.10A, and TIME BOOT RSC-MT8FS firmware version 1.00A to 1.00E), and Contact Converter(POSE SE10-8A7B1 firmware version 1.00A to 1.20A) allows a remote attac

Remediation

Check the references section for vendor advisories and patches from meikyo. Update watch_boot_nino_rpc-m2c_firmware to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
meikyo watch_boot_nino_rpc-m2cs_firmware 1.00a Affected
meikyo watch_boot_light_rpc-m5cs_firmware 1.00a Affected
meikyo watch_boot_l-zero_rpc-m4ls_firmware 1.00a Affected
meikyo poe_boot_nino_poe8m2_firmware 1.00a Affected

Frequently Asked Questions

What is CVE-2022-27632?

CVE-2022-27632 is a high-severity vulnerability affecting meikyo watch_boot_nino_rpc-m2c_firmware. It was published on May 18, 2022 and has a CVSS 3.1 base score of 8.8 (HIGH).

How severe is CVE-2022-27632?

This vulnerability has a CVSS 3.1 base score of 8.8, rated HIGH. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.

How do I fix or remediate CVE-2022-27632?

Check the references section for vendor advisories and patches from meikyo. Update watch_boot_nino_rpc-m2c_firmware to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2022-27632?

CyberStrike's AI-powered security agents can automatically detect CVE-2022-27632 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.