CVE-2022-50981Disclosure

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

An unauthenticated remote attacker can gain full access on the affected devices as they are shipped without a password by default and setting one is not enforced.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-02-02: 3PoC Mentioned / Linked · 2026-02-02: 1Technical Details · 2026-02-02: 302-02
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    General

    CVE-2022-50981 An unauthenticated remote attacker can gain full access on the affected devices as they are shipped without a password by default and setting one is not enforced. https://www.cve.org/CVERecord?id=CVE-2022-50981

    Post summary

    CVE-2022-50981 allows unauthenticated remote attackers to gain full access on devices shipped without enforced passwords; no PoC, exploit, patch, or active exploitation details are provided.

    00010192
    56.5K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2022-50981: CRITICAL] An unauthenticated remote attacker can gain full access on the affected devices as they are shipped without a password by default and setting one is not enforced.#cve,CVE-2022-50981,#cybersecurity https://cvefind.com/CVE-2022-50981

    Post summary

    The tweet discloses CVE‑2022‑50981, describing a critical vulnerability that allows unauthenticated remote attackers to gain full access due to devices shipped without passwords.

    00000201
    583 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2022-50981: Multiple Innomic VibroLine VLX H... Default credentials in VibroLine VLX HD devices = instant root for anyone with network access; shipping security-critic... https://zerodaysignal.com/vulnerability/CVE-2022-50981 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE-2022-50981, highlighting that default credentials on Innomic VibroLine VLX HD devices grant immediate root access, and directs readers to a link for further details.

    0000071
    132 followersView on X

Explore more