CVE-2022-32985
CRITICALNexans FTTO GigaSwitch <6.02N, <7.02 - Privilege Escalation
Title source: llmDescription
libnx_apl.so on Nexans FTTO GigaSwitch before 6.02N and 7.x before 7.02 implements a Backdoor Account for SSH logins on port 50200 or 50201.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_misc
https://www.nexans.de/de/products/Data-Network-Solutions/Industrial-and-office-switches.html
Exploit, Third Party Advisory x_refsource_misc
https://sec-consult.com/vulnerability-lab/advisory/hardcoded-backdoor-user-outdated-software-components-nexans-ftto-gigaswitch/
Scores
CVSS v3
9.8
EPSS
0.0103
EPSS Percentile
59.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-798
Status
published
Products (13)
nexans/gigaswitch_641_desk_v5_sfp-vi_firmware
< 6.02n
nexans/gigaswitch_642_desk_v5_sfp-2vi_firmware
< 6.02n
nexans/gigaswitch_v5_2tp\(pd-f\+\)_sfp-vi_54vdc_firmware
< 6.02n
nexans/gigaswitch_v5_2tp\(pse\+\)_sfp-vi_54vdc_firmware
< 6.02n
nexans/gigaswitch_v5_2tp_sfp-vi_54vdc_firmware
< 6.02n
nexans/gigaswitch_v5_sfp-2vi_230vac_firmware
< 6.02n
nexans/gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_firmware
< 6.02n
nexans/gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_ind_firmware
< 6.02n
nexans/gigaswitch_v5_tp\(pse\+\)_sfp-2vi_54vdc_med_firmware
< 6.02n
nexans/gigaswitch_v5_tp_sfp-2vi_54vdc_firmware
< 6.02n
... and 3 more
Published
Jul 17, 2022
Tracked Since
Feb 18, 2026