PT-2022-23236 · Contec · Contec Fxa3200

Samy Younsi

+1

·

Published

2022-09-15

·

Updated

2023-08-08

·

CVE-2022-36158

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Contec FXA3200 versions 1.13.00 and under
Description The issue allows malicious actors to execute Linux commands with root privilege via a hidden web page (/usr/www/ja/mnt cmd.cgi) in the Wireless LAN Manager interface due to Insecure Permissions. This enables attackers to gain elevated access.
Recommendations For Contec FXA3200 versions 1.13.00 and under, as a temporary workaround, consider restricting access to the hidden web page (/usr/www/ja/mnt cmd.cgi) until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

CVE-2022-36158

Affected Products

Contec Fxa3200