PT-2022-23283 · Airspan · Airspan Airspot 5410

Published

2022-08-08

·

Updated

2024-03-10

·

CVE-2022-36265

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Airspan AirSpot 5410 versions 0.3.4.1-4 and under
Description A hidden system command web page exists in the device, allowing an authenticated user to execute Linux commands with root privileges. This page is not listed in the administration management interface and can be used by a malicious threat actor to fully compromise the device.
Recommendations For Airspan AirSpot 5410 versions 0.3.4.1-4 and under, consider restricting access to the hidden system command web page until a patch is available. As a temporary workaround, limit the privileges of authenticated users to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Related Identifiers

CVE-2022-36265

Affected Products

Airspan Airspot 5410