CVE-2022-4098: Wut Com-Server ++ Firmware
High severity, CVSS 8.0. EPSS: 0.3% chance of exploitation in the next 30 days.
Multiple Wiesemann&Theis products of the ComServer Series are prone to an authentication bypass through IP spoofing. After a user logged in to the WBM of the Com-Server an unauthenticated attacker in the same subnet can obtain the session ID and through IP spoofing change arbitrary settings by crafting modified HTTP Get requests. This may result in a complete takeover of the device.
Affected products
- Wut Com-Server ++ Firmware: before 1.55 (fixed in 1.55)
- Wut Com-Server 20ma Firmware: before 1.55 (fixed in 1.55)
- Wut Com-Server Highspeed 100basefx Firmware: before 1.78 (fixed in 1.78)
- Wut Com-Server Highspeed 100baselx Firmware: before 1.78 (fixed in 1.78)
- Wut Com-Server Highspeed 19" 1port Firmware: before 1.78 (fixed in 1.78)
- Wut Com-Server Highspeed 19" 4port Firmware: before 1.78 (fixed in 1.78)
- Wut Com-Server Highspeed Compact Firmware: before 1.78 (fixed in 1.78)
- Wut Com-Server Highspeed Industry Firmware: before 1.78 (fixed in 1.78)
- Wut Com-Server Highspeed Isolated Firmware: before 1.78 (fixed in 1.78)
- Wut Com-Server Highspeed Lc Firmware: before 1.55 (fixed in 1.55)
- Wut Com-Server Highspeed Oem Firmware: before 1.78 (fixed in 1.78)
- Wut Com-Server Highspeed Office 1port Firmware: before 1.78 (fixed in 1.78)
- Wut Com-Server Highspeed Office 4port Firmware: before 1.78 (fixed in 1.78)
- Wut Com-Server Highspeed Poe 3x Isolated Firmware: before 1.55 (fixed in 1.55)
- Wut Com-Server Highspeed Poe Firmware: before 1.78 (fixed in 1.78)
- Wut Com-Server Highspeed Ul Firmware: before 1.55 (fixed in 1.55)
Published 2022-12-13. Last modified 2026-06-17.