9.8
CVSSv3

CVE-2022-32429

Published: 10/08/2022 Updated: 08/12/2022
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

An authentication-bypass issue in the component MYDEVICEIP/cgi-bin-sdb/ExportSettings.sh of Mega System Technologies Inc MSNSwitch MNT.2408 allows unauthenticated malicious users to arbitrarily configure settings within the application, leading to remote code execution.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

megatech msnswitch_firmware mnt.2408

Vendor Advisories

Check Point Reference: CPAI-2022-2002 Date Published: 22 Jan 2024 Severity: Critical ...

Exploits

Exploit Title: MSNSwitch Firmware MNT2408 - Remote Code Exectuion (RCE) Google Dork: n/a Date:9/1/2022 Exploit Author: Eli Fulkerson Vendor Homepage: wwwmsnswitchcom/ Version: MNT2408 Tested on: MNT2408 firmware CVE: CVE-2022-32429 #!/usr/bin/python3 """ POC for unauthenticated configuration dump, authenticated RCE on msnswitch fir ...
MSNSwitch Firmware MNT2408 suffers from a remote code execution vulnerability ...