CVE-2022-36309
Airspan AirVelocity 1500 software versions prior to 15.18.00.2511 have a root command injection vulnerability in the ActiveBank parameter of the recoverySubmit.cgi script running on the eNodeB's web management UI.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 24.6%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Airspan AirVelocity 1500 software versions prior to 15.18.00.2511 have a root command injection vulnerability in the ActiveBank parameter of the recoverySubmit.cgi script running on the eNodeB's web management UI. This issue may affect other AirVelocity and AirSpeed models.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 24.59% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- airspan/airvelocity 1500 firmware
- Source
- cve-assign@fb.com
References
- https://github.com/metaredteam/external-disclosures/security/advisories/GHSA-p295-2jh6-g6g4Exploit, Third Party Advisory
- https://helpdesk.airspan.com/browse/TRN3-1690Permissions Required, Vendor Advisory
- https://github.com/metaredteam/external-disclosures/security/advisories/GHSA-p295-2jh6-g6g4Exploit, Third Party Advisory
- https://helpdesk.airspan.com/browse/TRN3-1690Permissions Required, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.