CVE-2022-36265
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
08/08/2022
Last modified:
12/08/2022
Description
In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Hidden system command web page. After performing a reverse engineering of the firmware, it was discovered that a hidden page not listed in the administration management interface allows a user to execute Linux commands on the device with root privileges. An authenticated malicious threat actor can use this page to fully compromise the device.
Impact
Base Score 3.x
7.20
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:airspan:airspot_5410_firmware:*:*:*:*:*:*:*:* | 0.3.4.1-4 (including) | |
| cpe:2.3:h:airspan:airspot_5410:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



