Airspan AirSpot 5410是美国Airspan公司的一款先进的 LTE、CAT12、户外、多服务产品。 Airspan AirSpot 5410 0.3.4.1-4及以前版本存在安全漏洞,该漏洞源于二进制组件/home/www/cgi-bin/diagnostics.cgi可以接收未经身份验证的请求和未经消毒的数据导致未经身份验证的攻击者编写恶意http请求进行远程命令注入来调用ping功能。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | PoC Script for CVE-2022-36267: Exploits an unauthenticated remote command injection vulnerability in Airspan AirSpot 5410 antenna. | https://github.com/0xNslabs/CVE-2022-36267-PoC | POC Details |
No public POC found.
Login to generate AI POC| CVE-2022-35487 | Zammad 安全漏洞 | |
| CVE-2022-35488 | Zammad 资源管理错误漏洞 | |
| CVE-2022-35489 | Zammad 安全漏洞 | |
| CVE-2022-35490 | Zammad 安全漏洞 | |
| CVE-2022-35493 | WRTeam eShop 跨站脚本漏洞 | |
| CVE-2022-36266 | Airspan AirSpot 5410 跨站脚本漏洞 | |
| CVE-2022-36265 | Airspan AirSpot 5410 安全漏洞 | |
| CVE-2022-36264 | Airspan AirSpot 5410 代码问题漏洞 | |
| CVE-2022-34293 | Wolfssl 安全漏洞 | |
| CVE-2021-41615 | Embedthis Software GoAhead 安全特征问题漏洞 |
No comments yet