PT-2022-23283 · Airspan · Airspan Airspot 5410
Published
2022-08-08
·
Updated
2024-03-10
·
CVE-2022-36265
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Airspan AirSpot 5410 versions 0.3.4.1-4 and under
Description
A hidden system command web page exists in the device, allowing an authenticated user to execute Linux commands with root privileges. This page is not listed in the administration management interface and can be used by a malicious threat actor to fully compromise the device.
Recommendations
For Airspan AirSpot 5410 versions 0.3.4.1-4 and under, consider restricting access to the hidden system command web page until a patch is available. As a temporary workaround, limit the privileges of authenticated users to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Airspan Airspot 5410