← Global Threat Landscape

CVE-2022-28810

CWE-78

High

85.5

RPS

Description

Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYSTEM via the policy custom script feature. Due to the use of a default administrator password, attackers may be able to abuse this functionality with minimal effort. Additionally, a remote and partially authenticated attacker may be able to inject arbitrary commands into the custom script due to an unsanitized password field.

Source: NVD

Signals

CVSS
6.8
Medium · v3.1
EPSS
70.96%
Probability of exploitation in the next 30 days (FIRST)
CISA KEV
In CISA KEV since Mar 2023
Fix commit
No known fix commit
Sources: MoreFixes, FreshFixes
Weakness
CWE-78
CWE-78, CWE-798
Published
18 Apr 2022
Last modified 31 Oct 2025

How to read these signals: RPS · EPSS · CISA KEV · Data sources

Get this score from the API

curl -H "Authorization: Bearer dsec_live_xxxxxxxx" \
  https://api.intelligence.devsecure.io/api/v1/rps/CVE-2022-28810

Replace the placeholder with your key. Get a free API key or rank your own CVEs.

Data as of 7 Oct 2026, 05:16 UK time

CVE-2022-28810 · RPS 85.5 · DevSecure Intelligence