CVE-2022-36265 Details
Description
In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Hidden system command web page. After performing a reverse engineering of the firmware, it was discovered that a hidden page not listed in the administration management interface allows a user to execute Linux commands on the device with root privileges. An authenticated malicious threat actor can use this page to fully compromise the device.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gist.github.com/Nwqda/e82b3155401b094372195fdaa9b54833 | CVE | ExploitMitigationThird Party Advisory |
| https://wdi.rfwel.com/cdn/techdocs/AirSpot5410.pdf | CVE | ProductThird Party Advisory |
| https://gist.github.com/Nwqda/e82b3155401b094372195fdaa9b54833 | [email protected] | ExploitMitigationThird Party Advisory |
| https://wdi.rfwel.com/cdn/techdocs/AirSpot5410.pdf | [email protected] | ProductThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| airspan airspot 5410 firmware | <= 0.3.4.1-4 |
CPE
Remediation
| |
| airspan airspot 5410 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Aug 12, 2022 | Initial Analysis | [email protected] |