CVE-2022-36309
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD
Description
Airspan AirVelocity 1500 software versions prior to 15.18.00.2511 have a root command injection vulnerability in the ActiveBank parameter of the recoverySubmit.cgi script running on the eNodeB's web management UI. This issue may affect other AirVelocity and AirSpeed models.
Affected (1)
Products: Airspan: Airvelocity 1500 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 9.3.0.01249 to 15.18.00.2511 |
| Running on/with | Platform Versions |
|---|---|
Airspan Airvelocity 1500 | All versions |
References (4)
Source: cve-assign@fb.com
ExploitThird Party Advisory
Source: cve-assign@fb.com
Permissions RequiredVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions RequiredVendor Advisory
Timeline
No history available yet.