CVE-2022-36158

Severity CVSS v4.0:
Pending analysis
Type:
CWE-425 Direct Request ('Forced Browsing')
Publication date:
26/09/2022
Last modified:
21/05/2025

Description

Contec FXA3200 version 1.13.00 and under suffers from Insecure Permissions in the Wireless LAN Manager interface which allows malicious actors to execute Linux commands with root privilege via a hidden web page (/usr/www/ja/mnt_cmd.cgi).

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:contec:fxa3000_firmware:*:*:*:*:*:*:*:* 1.13.00 (including)
cpe:2.3:h:contec:fxa3000:-:*:*:*:*:*:*:*
cpe:2.3:o:contec:fxa3020_firmware:*:*:*:*:*:*:*:* 1.13.00 (including)
cpe:2.3:h:contec:fxa3020:-:*:*:*:*:*:*:*
cpe:2.3:o:contec:fxa3200_firmware:*:*:*:*:*:*:*:* 1.13.00 (including)
cpe:2.3:h:contec:fxa3200:-:*:*:*:*:*:*:*
cpe:2.3:o:contec:fxa2000_firmware:*:*:*:*:*:*:*:* 1.39.00 (excluding)
cpe:2.3:h:contec:fxa2000:-:*:*:*:*:*:*:*