High severity7.2NVD Advisory· Published Apr 25, 2023· Updated Jun 17, 2026
CVE-2022-45291
CVE-2022-45291
Description
PWS Personal Weather Station Dashboard (PWS_Dashboard) LTS December 2020 (2012_lts) allows remote code execution by injecting PHP code into settings.php. Attacks can use the PWS_printfile.php, PWS_frame_text.php, PWS_listfile.php, PWS_winter.php, and PWS_easyweathersetup.php endpoints. A contributing factor is a hardcoded login password of support, which is not documented. (This is not the same as the documented setup password, which is 12345.) The issue was fixed in late 2022.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:pwsdashboard:personal_weather_station_dashboard:-:*:*:*:*:*:*:*
- PWS/Personal Weather Station Dashboarddescription
- Range: LTS December 2020 (2012_lts)
Patches
Vulnerability mechanics
References
2- cavefxa.com/posts/cve-2022-45291/nvdExploitTechnical DescriptionThird Party Advisory
- pwsdashboard.comnvdProduct
News mentions
0No linked articles in our index yet.