CVE-2022-28811: Gavazziautomation Cpy Car Park Server

Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.

In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could utilize an improper input validation on an API-submitted parameter to execute arbitrary OS commands.

Affected products

  • Gavazziautomation Cpy Car Park Server: before 2.8.3 (fixed in 2.8.3)
  • Gavazziautomation Uwp 3.0 Monitoring Gateway And Controller Firmware: before 8.5.0.3 (fixed in 8.5.0.3)

Published 2022-09-28. Last modified 2026-06-17.