CVE-2022-30236
A CWE-669: Incorrect Resource Transfer Between Spheres vulnerability exists that could allow unauthorized access when an attacker uses cross-domain attacks. Affected Products: Wiser Smart, EER21000 & EER21001 (V4.5 and prior)
Scoring
- Severity
- HIGH
- CVSS base score
- 8.2
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
- EPSS probability
- 0.51%
- CWE
- CWE-669
- Published
- 2022-06-02
- Last modified
- 2026-03-13
Affected products
- Schneider Electric Wiser Smart
- Schneider Electric Wiser Smart
Weakness type
Related vulnerabilities
- CVE-2025-41660 — CODESYS Control Boot Application Replacement Enables Code Execution
- CVE-2026-25253 — OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically mak
- CVE-2025-41645 — SMA: Sunny Portal demo system privilege escalation
- CVE-2025-34158 — Plex Media Server (PMS) 1.41.7.x through 1.42.0.x before 1.42.1 is affected by incorrect resource transfer between spher
- CVE-2025-67895 — Apache Airflow Providers Edge3: Edge3 Worker RPC RCE on Airflow 2
- CVE-2025-62775 — Mercku M6a devices through 2.1.0 allow root TELNET logins via the web admin password.
- CVE-2024-38519 — yt-dlp and youtube-dl vulnerable to file system modification and RCE through improper file-extension sanitization
- CVE-2025-59363 — In One Identity OneLogin before 2025.3.0, a request returns the OIDC client secret with GET Apps API v2 (even though thi