CVE-2023-36622 | Loxone Miniserver Go Gen.2 prior 14.1.5.9 Websocket Configuration Endpoint timezone os command injection (SYSS-2023-012 / EUVD-2023-40566)
A vulnerability classified as critical was found in Loxone Miniserver Go Gen.2. The affected element is an unknown function of the component Websocket Configuration Endpoint. Such manipulation of the argument timezone leads to os command injection.
This vulnerability is referenced as CVE-2023-36622. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is advised.