Airspan AirVelocity 1500 software versions prior to 15.18.00.2511 have a root command injection vulnerability in the ActiveBank parameter of the recoverySubmit.cgi script running on the eNodeB's web management UI. This issue may affect other AirVelocity and AirSpeed models.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: facebook

Published: 2022-08-16T00:33:24

Updated: 2022-08-16T00:33:24

Reserved: 2022-07-19T00:00:00


Link: CVE-2022-36309

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-08-16T01:15:13.707

Modified: 2022-08-17T14:19:11.527


Link: CVE-2022-36309

JSON object: View

cve-icon Redhat Information

No data.

CWE