Airspan AirVelocity 1500 software versions prior to 15.18.00.2511 have a root command injection vulnerability in the ActiveBank parameter of the recoverySubmit.cgi script running on the eNodeB's web management UI. This issue may affect other AirVelocity and AirSpeed models.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: facebook

Published: 2022-08-16T00:33:24

Updated: 2024-08-03T10:00:04.309Z

Reserved: 2022-07-19T00:00:00

Link: CVE-2022-36309

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-08-16T01:15:13.707

Modified: 2022-08-17T14:19:11.527

Link: CVE-2022-36309

cve-icon Redhat

No data.