CVE-2022-36308

CRITICAL

Airspan AirVelocity <15.18.00.2511 - Info Disclosure

Title source: llm

Description

Airspan AirVelocity 1500 web management UI displays SNMP credentials in plaintext on software versions older than 15.18.00.2511, and stores SNMPv3 credentials unhashed on the filesystem, enabling anyone with web access to use these credentials to manipulate the eNodeB over SNMP. This issue may affect other AirVelocity and AirSpeed models.

Scores

CVSS v3 9.1
EPSS 0.0026
EPSS Percentile 49.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Classification

CWE
CWE-522 CWE-256
Status published

Affected Products (1)

airspan/airvelocity_1500_firmware < 15.18.00.2511

Timeline

Published Aug 16, 2022
Tracked Since Feb 18, 2026