CRITICAL

CVE-2022-36267

CVSS v3

9.8

CRITICAL

EPSS Score

70.2%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Unauthenticated remote command injection vulnerability. The ping functionality can be called without user authentication when crafting a malicious http request by injecting code in one of the parameters allowing for remote code execution. This vulnerability is exploited via the binary file /home/www/cgi-bin/diagnostics.cgi that accepts unauthenticated requests and unsanitized data. As a result, a malicious actor can craft a specific request and interact remotely with the device.

Technical details

Published
8/8/2022

Frequently asked questions

What is CVE-2022-36267?

In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Unauthenticated remote command injection vulnerability. The ping functionality can be called without user authentication when crafting a malicious http request by injecting code in one of the parameters allowing for remote code execution. This vulnerability is exploited via the binary file /home/www/cgi-bin/diagnostics.cgi that accepts unauthenticated requests and unsanitized data. As a result, a malicious actor can craft a specific request and interact remotely with the device.

Is CVE-2022-36267 actively exploited?

Active exploitation of CVE-2022-36267 has not been confirmed. The EPSS score is 70.2%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2022-36267?

CVE-2022-36267 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2022-36267 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.