Airspan AirVelocity 1500 software versions prior to 15.18.00.2511 have a root command injection vulnerability in the ActiveBank parameter of the recoverySubmit.cgi script running on the eNodeB's web management UI. This issue may affect other AirVelocity and AirSpeed models.
References
Link | Resource |
---|---|
https://github.com/metaredteam/external-disclosures/security/advisories/GHSA-p295-2jh6-g6g4 | Exploit Third Party Advisory |
https://helpdesk.airspan.com/browse/TRN3-1690 | Permissions Required Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: facebook
Published: 2022-08-16T00:33:24
Updated: 2022-08-16T00:33:24
Reserved: 2022-07-19T00:00:00
Link: CVE-2022-36309
JSON object: View
NVD Information
Status : Analyzed
Published: 2022-08-16T01:15:13.707
Modified: 2022-08-17T14:19:11.527
Link: CVE-2022-36309
JSON object: View
Redhat Information
No data.
CWE