CVE Database
/

CVE-2022-36309

Back to search

CVE-2022-36309

Published: Aug 16, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

Airspan AirVelocity 1500 software versions prior to 15.18.00.2511 have a root command injection vulnerability in the ActiveBank parameter of the recoverySubmit.cgi script running on the eNodeB's web management UI. This issue may affect other AirVelocity and AirSpeed models.

VendorProductVersions

Airspan

AirVelocity

affected
unspecified - < 15.18.00.2511

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now