NA

CVE-2022-36265

Published: 08/08/2022 Updated: 12/08/2022
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 0

Vulnerability Summary

In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Hidden system command web page. After performing a reverse engineering of the firmware, it exists that a hidden page not listed in the administration management interface allows a user to execute Linux commands on the device with root privileges. An authenticated malicious threat actor can use this page to fully compromise the device.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

airspan airspot_5410_firmware