Multiple W&T products of the Comserver Series use a small number space for allocating sessions ids. After login of an user an unathenticated remote attacker can brute force the users session id and get access to his account on the the device. As the user needs to log in for the attack to be successful a user interaction is required.
Conclusion & alert: CVE-2022-42787 is rated Moderate Risk (62/100): CVSS High severity, with medium exploitation likelihood (EPSS 0.91%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-03-10 | 0.58% | 0.91% | +0.33% |
| 2 | 2025-12-29 | 0.91% | 0.58% | -0.34% |
| 3 | 2025-11-21 | — | 0.91% | — |
Full EPSS history (17 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.8 | 3.1 | HIGH |
|
2.8 | 5.9 | [email protected] |
| 8.8 | 3.1 | HIGH |
|
2.8 | 5.9 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| wut | at-modem-emulator_firmware | < 1.48 | cpe:2.3:o:wut:at-modem-emulator_firmware:*:*:*:*:*:*:*:* |
| wut | com-server_\+\+_firmware | < 1.48 | cpe:2.3:o:wut:com-server_\+\+_firmware:*:*:*:*:*:*:*:* |
| wut | com-server_20ma_firmware | < 1.48 | cpe:2.3:o:wut:com-server_20ma_firmware:*:*:*:*:*:*:*:* |
| wut | com-server_highspeed_100basefx_firmware | < 1.76 | cpe:2.3:o:wut:com-server_highspeed_100basefx_firmware:*:*:*:*:*:*:*:* |
| wut | com-server_highspeed_100baselx_firmware | < 1.76 | cpe:2.3:o:wut:com-server_highspeed_100baselx_firmware:*:*:*:*:*:*:*:* |
| wut | com-server_highspeed_19\"_1port_firmware | < 1.76 | cpe:2.3:o:wut:com-server_highspeed_19\"_1port_firmware:*:*:*:*:*:*:*:* |
| wut | com-server_highspeed_19\"_4port_firmware | < 1.76 | cpe:2.3:o:wut:com-server_highspeed_19\"_4port_firmware:*:*:*:*:*:*:*:* |
| wut | com-server_highspeed_compact_firmware | < 1.76 | cpe:2.3:o:wut:com-server_highspeed_compact_firmware:*:*:*:*:*:*:*:* |
| wut | com-server_highspeed_industry_firmware | < 1.76 | cpe:2.3:o:wut:com-server_highspeed_industry_firmware:*:*:*:*:*:*:*:* |
| wut | com-server_highspeed_isolated_firmware | < 1.76 | cpe:2.3:o:wut:com-server_highspeed_isolated_firmware:*:*:*:*:*:*:*:* |
| wut | com-server_highspeed_oem_firmware | < 1.76 | cpe:2.3:o:wut:com-server_highspeed_oem_firmware:*:*:*:*:*:*:*:* |
| wut | com-server_highspeed_office_1port_firmware | < 1.76 | cpe:2.3:o:wut:com-server_highspeed_office_1port_firmware:*:*:*:*:*:*:*:* |
| wut | com-server_highspeed_office_4port_firmware | < 1.76 | cpe:2.3:o:wut:com-server_highspeed_office_4port_firmware:*:*:*:*:*:*:*:* |
| wut | com-server_highspeed_poe_firmware | < 1.76 | cpe:2.3:o:wut:com-server_highspeed_poe_firmware:*:*:*:*:*:*:*:* |
| wut | com-server_highspeed_lc_firmware | < 1.48 | cpe:2.3:o:wut:com-server_highspeed_lc_firmware:*:*:*:*:*:*:*:* |
| wut | com-server_highspeed_ul_firmware | < 1.48 | cpe:2.3:o:wut:com-server_highspeed_ul_firmware:*:*:*:*:*:*:*:* |
| wut | com-server_highspeed_poe_3x_isolated_firmware | < 1.48 | cpe:2.3:o:wut:com-server_highspeed_poe_3x_isolated_firmware:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://cert.vde.com/de/advisories/VDE-2022-043 | Vendor Advisory |