Record summary

CVE-2022-36267 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit and 1 repository PoC.

Description

In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Unauthenticated remote command injection vulnerability. The ping functionality can be called without user authentication when crafting a malicious http request by injecting code in one of the parameters allowing for remote code execution. This vulnerability is exploited via the binary file /home/www/cgi-bin/diagnostics.cgi that accepts unauthenticated requests and unsanitized data. As a result, a malicious actor can craft a specific request and interact remotely with the device.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Feb 15, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Catalogued exploits
1
Repository PoCs
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Proofs of concept

2

Catalogued exploits

ExploitDBAirspan AirSpot 5410 version 0.3.4.1 - Remote Code Execution (RCE)ExploitDB exploitby Samy YounsiNot analyzed1 file
ExploitDB

PoC details

Repository PoCs

GitHub0xNslabs/CVE-2022-36267-PoCRepository PoCby 0xNslabsStars: 12Not analyzed2 files

4.3 KiB

GitHub

PoC details

References

4