CVE-2022-32429
MSNSwitch Firmware MNT.2408 - Remote Code Execution
Record summary
CVE-2022-32429 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Description
An authentication-bypass issue in the component http://MYDEVICEIP/cgi-bin-sdb/ExportSettings.sh of Mega System Technologies Inc MSNSwitch MNT.2408 allows unauthenticated attackers to arbitrarily configure settings within the application, leading to remote code execution.
Exploitation context
Proofs of concept
1Catalogued exploits
ExploitDBMSNSwitch Firmware MNT.2408 - Remote Code ExecutionExploitDB exploitby Eli FulkersonNot analyzed1 file
Nuclei templates
1ProjectDiscoveryCRITICALMSNSwitch Firmware MNT.2408 - Authentication BypassCVSS 9.8
MSNSwitch Firmware MNT.2408 is susceptible to authentication bypass in the component http://MYDEVICEIP/cgi-bin-sdb/ExportSettings.sh. An attacker can arbitrarily configure settings, leading to possible remote code execution and subsequent unauthorized operations.
Impact
Successful exploitation of this vulnerability allows an attacker to bypass authentication and gain unauthorized access to the affected device.
Remediation
Apply the latest firmware update provided by the vendor to fix the authentication bypass vulnerability.
Source: ProjectDiscovery