Vulnerabilities > Airspan > A5X Firmware > Critical

DATE CVE VULNERABILITY TITLE RISK
2022-02-18 CVE-2022-21215 Server-Side Request Forgery (SSRF) vulnerability in Airspan products
This vulnerability could allow an attacker to force the server to create and execute a web request granting access to backend APIs that are only accessible to the Mimosa MMP server, or request pages that could perform some actions themselves.
network
low complexity
airspan CWE-918
critical
10.0
2022-02-18 CVE-2022-21196 Unspecified vulnerability in Airspan products
MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does not perform proper authorization and authentication checks on multiple API routes.
network
low complexity
airspan
critical
9.8
2022-02-18 CVE-2022-21143 OS Command Injection vulnerability in Airspan products
MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does not properly sanitize user input on several locations, which may allow an attacker to inject arbitrary commands.
network
low complexity
airspan CWE-78
critical
10.0
2022-02-18 CVE-2022-21141 Incorrect Authorization vulnerability in Airspan products
MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does not perform proper authorization checks on multiple API functions.
network
low complexity
airspan CWE-863
critical
10.0