7.2
CVE-2022-36265
- EPSS 0.51%
- Veröffentlicht 08.08.2022 15:15:08
- Zuletzt bearbeitet 21.11.2024 07:12:41
- Quelle cve@mitre.org
- Teams Watchlist Login
- Unerledigt Login
In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Hidden system command web page. After performing a reverse engineering of the firmware, it was discovered that a hidden page not listed in the administration management interface allows a user to execute Linux commands on the device with root privileges. An authenticated malicious threat actor can use this page to fully compromise the device.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Airspan ≫ Airspot 5410 Firmware Version <= 0.3.4.1-4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.51% | 0.653 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7.2 | 1.2 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|