Showing 1 vulnerability on this page for airspot_5410_firmware

Signals CISA KEV Ransomware Nuclei
Airspan vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Airspan AirSpot 5410 version 0.3.4.1-4 and under Remote Code Execution

In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Unauthenticated remote command injection vulnerability. The ping functionality can be called without user authentication when crafting a malicious http request by injecting code in one of the parameters allowing for remote code execution. This vulnerability is exploited via the binary file /home/www/cgi-bin/diagnostics.cgi that accepts unauthenticated requests and unsanitized data. As a result, a malicious actor can craft a speci

CWE-77Aug 8, 2022
CVSS9.8v3.1EPSS53.8%PoCs2SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX