CVE-2022-36265

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
08/08/2022
Last modified:
12/08/2022

Description

In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Hidden system command web page. After performing a reverse engineering of the firmware, it was discovered that a hidden page not listed in the administration management interface allows a user to execute Linux commands on the device with root privileges. An authenticated malicious threat actor can use this page to fully compromise the device.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:airspan:airspot_5410_firmware:*:*:*:*:*:*:*:* 0.3.4.1-4 (including)
cpe:2.3:h:airspan:airspot_5410:-:*:*:*:*:*:*:*