packetstormsecurity.com
http://packetstormsecurity.com/files/168047/AirSpot-5410-0.3.4.1-4-Remote-Command-Injection.html CVE-2022-36267
CRITICAL
Airspan AirSpot 5410 version 0.3.4.1-4 and under Remote Code Execution
Record summary
CVE-2022-36267 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit and 1 repository PoC.
Description
In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Unauthenticated remote command injection vulnerability. The ping functionality can be called without user authentication when crafting a malicious http request by injecting code in one of the parameters allowing for remote code execution. This vulnerability is exploited via the binary file /home/www/cgi-bin/diagnostics.cgi that accepts unauthenticated requests and unsanitized data. As a result, a malicious actor can craft a specific request and interact remotely with the device.
Description source: CVE List
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
airspot_5410_firmwareBrowse airspan / airspot_5410_firmware | VulnCheck | Version data not supplied | |
Proofs of concept
2Catalogued exploits
ExploitDBAirspan AirSpot 5410 version 0.3.4.1 - Remote Code Execution (RCE)ExploitDB exploitby Samy YounsiNot analyzed1 file
Repository PoCs
GitHub0xNslabs/CVE-2022-36267-PoCRepository PoCby 0xNslabsStars: 12Not analyzed2 files
References
4gist.github.com
https://gist.github.com/Nwqda/e82b3155401b094372195fdaa9b54833 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-36267 wdi.rfwel.com
https://wdi.rfwel.com/cdn/techdocs/AirSpot5410.pdf