Improper access control in Crypto Application Server (CAS) - CVE-2022-4980
Published: August 22, 2022 / Updated: September 20, 2026
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to improper access restrictions to the default installation page. A remote attacker can connect to the default installation URL and create an administrative user account.
Note, the vulnerability is being active exploited in the wild.