Описание
Airspan AirVelocity 1500 software versions prior to 15.18.00.2511 have a root command injection vulnerability in the ActiveBank parameter of the recoverySubmit.cgi script running on the eNodeB's web management UI. This issue may affect other AirVelocity and AirSpeed models.
Ссылки
- ExploitThird Party Advisory
- Permissions RequiredVendor Advisory
- ExploitThird Party Advisory
- Permissions RequiredVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 9.3.0.01249 (включая) до 15.18.00.2511 (включая)
Одновременно
cpe:2.3:o:airspan:airvelocity_1500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:airspan:airvelocity_1500:-:*:*:*:*:*:*:*
EPSS
Процентиль: 95%
0.17729
Средний
8.8 High
CVSS3
Дефекты
CWE-78
CWE-78
EPSS
Процентиль: 95%
0.17729
Средний
8.8 High
CVSS3
Дефекты
CWE-78
CWE-78