CVE-2022-29540: resi-calltrace in RESI Gemini-Net 4.2 is affected by Multiple XSS issues. Unauthenticated remote attackers can inject ar
mediumvulnerability
security
Summary
CVE-2022-29540 is a cross-site scripting vulnerability (XSS, where attackers inject malicious code into web pages) in RESI Gemini-Net 4.2 that allows unauthenticated remote attackers to inject arbitrary web scripts or HTML through HTTP GET parameters without proper input validation. The vulnerability affects multiple application endpoints and has a CVSS score (severity rating on a 0-10 scale) of 4.0.
Vulnerability Details
CVSS Score
6.1(medium)
EPSS (30-day exploit probability)
EPSS: 1.1%
Classification
Attack SophisticationTrivial
Original source: https://nvd.nist.gov/vuln/detail/CVE-2022-29540
First tracked: February 15, 2026 at 08:51 PM
Classified by LLM (prompt v3) · confidence: 95%