CVE-2022-31486

HIGH

An authenticated attacker can send a specially crafted route to the “edit_route.cgi” binary and have it execute shell commands. This vulnerability impacts products based on HID Mercury Intelligent ...

Affects 28 products across 3 vendors.

BCS7.32
CVSS 3.18.8
EPSS1.2%
Percentile66th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, low privileges required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-78: OS Command Injection

Attacker injects OS commands through application inputs passed to system() or equivalent calls, leading to arbitrary command execution.

Related Attack Patterns (CAPEC)
CAPEC-43 Exploiting Multiple Input Interpretation Layers
via CWE-78
CAPEC-108 Command Line Execution through SQL Injection
via CWE-78
CAPEC-6 Argument Injection
via CWE-78
CAPEC-15 Command Delimiters
via CWE-78
CAPEC-88 OS Command Injection
via CWE-78

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

CVE-2022-31486 affects HID Mercury Intelligent Controllers, allowing an authenticated attacker to execute arbitrary shell commands via a specially crafted route to the 'edit_route.cgi' binary. This can lead to monitoring, modification, and instability of the device. Firmware versions prior to 1.303 for LP series and 1.297 for EP series are vulnerable.

BSID: BS-2022-GLOBAL-319391-H • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2022-31486?
CVE-2022-31486 affects HID Mercury Intelligent Controllers, allowing an authenticated attacker to execute arbitrary shell commands via a specially crafted route to the 'edit_route.cgi' binary. This can lead to monitoring, modification, and instability of the device. Firmware versions prior to 1.303 for LP series and 1.297 for EP series are vulnerable.
What is the CVSS score for CVE-2022-31486?
CVE-2022-31486 has CVSS 8.8 (High). Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. EPSS: 1.2%.
Is CVE-2022-31486 actively exploited?
No confirmed active exploitation of CVE-2022-31486 as of 2026-05-30.
How do I remediate CVE-2022-31486?
Priority: HIGH. Advisory: https://www.corporate.carrier.com/product-security/advisories-resources/ PSIRT: [email protected]
What systems are affected by CVE-2022-31486?
CVE-2022-31486 affects: Carrier, Carrier, Carrier, Carrier, Carrier, Carrier, Carrier, Carrier.
What NERC-CIP standard applies to CVE-2022-31486?
NERC CIP CIP-007 CIP-007-R2: This CVE violates CIP-007-R2 as it allows unauthorized access to the control system, potentially leading to the compromise of critical functions and data.
What IEC 62443 requirement maps to CVE-2022-31486?
IEC 62443 SR 7.6: This CVE maps to SR 7.6 because it involves the protection of the control system from unauthorized access and manipulation, which can lead to operational disruptions and safety risks.
Vulnerability Details
CVE IDCVE-2022-31486
BSIDBS-2022-GLOBAL-319391-H BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Published2022-06-06
Last Modified2024-11-21
ICS Relevance90%
Weakness (CWE)
Verticals
ICS-OT
SourceNVD
Official Description

An authenticated attacker can send a specially crafted route to the “edit_route.cgi” binary and have it execute shell commands. This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 which contain firmware versions prior to 1.303 for the LP series and 1.297 for the EP series. An attacker with this level of access on the device can monitor all communications sent to and from this device, modify onboard relays, change configuration files, or cause the device to become unstable.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

An authenticated attacker can exploit this vulnerability by sending a specially crafted route to the 'edit_route.cgi' binary, leading to the execution of arbitrary shell commands. This can result in the attacker gaining full control over the device, including monitoring communications, modifying onboard relays, changing configuration files, and causing the device to become unstable.

Exploitation Likelihood: MEDIUM

Affected Products
VendorProductFixed Version
Carrier Lenels2 S2-Lp-4502
Carrier Lenels2 Lnl-4420 Firmware
Carrier Lenels2 Lnl-4420
Carrier Lenels2 Lnl-X2210 Firmware
Carrier Lenels2 Lnl-X2210
Carrier Lenels2 Lnl-X2220 Firmware
Carrier Lenels2 Lnl-X2220
Carrier Lenels2 Lnl-X3300 Firmware
Carrier Lenels2 Lnl-X3300
Carrier Lenels2 Lnl-X4420 Firmware
Carrier Lenels2 Lnl-X4420
Carrier Lenels2 S2-Lp-1501 Firmware
Carrier Lenels2 S2-Lp-1501
Carrier Lenels2 S2-Lp-1502 Firmware
Carrier Lenels2 S2-Lp-1502
Carrier Lenels2 S2-Lp-2500 Firmware
Carrier Lenels2 S2-Lp-2500
Carrier Lenels2 S2-Lp-4502 Firmware
Hidglobal Ep4502
Hidglobal Lp1501 Firmware
Hidglobal Lp1501
Hidglobal Lp1502 Firmware
Hidglobal Lp1502
Hidglobal Lp2500 Firmware
Hidglobal Lp2500
Hidglobal Lp4502 Firmware
Hidglobal Lp4502
Hidglobal Ep4502 Firmware
Honeywell —
Remediation
View Vendor Advisory →

Remediation Priority: HIGH

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 1510 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
● Virtual Patch — CITED Relevance SAGE Engine MEDIUM CONFIDENCE

Implement strict input validation and sanitization for the 'edit_route.cgi' endpoint to prevent the execution of arbitrary shell commands. Additionally, restrict access to this endpoint to only trusted users and IP addresses.

SURICATA RULE
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"CVE-2022-31486 - HID Mercury Controller edit_route.cgi command injection attempt"; flow:established,to_server; content:"/edit_route.cgi"; http_uri; content:"route="; http_uri; sid:9100262; rev:1;)
NERC CIP: CIP-007 CIP-007-R2
This CVE violates CIP-007-R2 as it allows unauthorized access to the control system, potentially leading to the compromise of critical functions and data.
IEC 62443: SR 7.6
This CVE maps to SR 7.6 because it involves the protection of the control system from unauthorized access and manipulation, which can lead to operational disruptions and safety risks.

Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.

SAGE Enrichment Record — provenance & audit hash
ModelQwen/Qwen2.5-72B-Instruct-AWQ
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash1574168c8cf870a666a8fe206b54e21d5f375228ef6dda70f8bcb24224744296308e455730d6f8da054787cd2f00b165a3d24645b512d39d624a8fab5686539e
Related CVEs affecting Carrier
CVE-2022-31481 10.0 An unauthenticated attacker can send a specially crafted update file to the d... CVE-2025-53213 9.9 Unrestricted Upload of File with Dangerous Type vulnerability in ELEXtensions... CVE-2022-31479 9.8 An unauthenticated attacker can update the hostname with a specially crafted ... CVE-2022-31483 8.8 An authenticated attacker can upload a file with a filename including “..” an... CVE-2017-9650 7.8 An Unrestricted Upload of File with Dangerous Type issue was discovered in Au...
View all Carrier CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.

Join free →