7.2

CVE-2022-36265

Exploit
In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Hidden system command web page. After performing a reverse engineering of the firmware, it was discovered that a hidden page not listed in the administration management interface allows a user to execute Linux commands on the device with root privileges. An authenticated malicious threat actor can use this page to fully compromise the device.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AirspanAirspot 5410 Firmware Version <= 0.3.4.1-4
   AirspanAirspot 5410 Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.55% 0.675
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://gist.github.com/Nwqda/e82b3155401b094372195fdaa9b54833
Third Party Advisory
Exploit
Mitigation
https://wdi.rfwel.com/cdn/techdocs/AirSpot5410.pdf
Third Party Advisory
Product