Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qc88-pvp2-9954

Опубликовано: 09 авг. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Hidden system command web page. After performing a reverse engineering of the firmware, it was discovered that a hidden page not listed in the administration management interface allows a user to execute Linux commands on the device with root privileges. An authenticated malicious threat actor can use this page to fully compromise the device.

In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Hidden system command web page. After performing a reverse engineering of the firmware, it was discovered that a hidden page not listed in the administration management interface allows a user to execute Linux commands on the device with root privileges. An authenticated malicious threat actor can use this page to fully compromise the device.

EPSS

Процентиль: 68%
0.00576
Низкий

7.2 High

CVSS3

Связанные уязвимости

CVSS3: 7.2
nvd
больше 3 лет назад

In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Hidden system command web page. After performing a reverse engineering of the firmware, it was discovered that a hidden page not listed in the administration management interface allows a user to execute Linux commands on the device with root privileges. An authenticated malicious threat actor can use this page to fully compromise the device.

EPSS

Процентиль: 68%
0.00576
Низкий

7.2 High

CVSS3