Airspan Vulnerabilities and Affected Products
Vulnerabilities associated with airspot_5410_firmware.
Products
Clear product- AirVelocity7 vulnerabilities
- airspot_5410_firmware1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2022-36267CRITICAL | Airspan AirSpot 5410 version 0.3.4.1-4 and under Remote Code ExecutionIn Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Unauthenticated remote command injection vulnerability. The ping functionality can be called without user authentication when crafting a malicious http request by injecting code in one of the parameters allowing for remote code execution. This vulnerability is exploited via the binary file /home/www/cgi-bin/diagnostics.cgi that accepts unauthenticated requests and unsanitized data. As a result, a malicious actor can craft a speci… CWE-77Aug 8, 2022 | CVSS9.8v3.1 | EPSS53.8% | PoCs2 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |