Vulnerabilities > Airspan > Critical

DATE CVE VULNERABILITY TITLE RISK
2022-08-08 CVE-2022-36267 Unspecified vulnerability in Airspan Airspot 5410 Firmware 0.3.4.14
In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Unauthenticated remote command injection vulnerability.
network
low complexity
airspan
critical
9.8
2022-02-18 CVE-2022-21141 Incorrect Authorization vulnerability in Airspan products
MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does not perform proper authorization checks on multiple API functions.
network
low complexity
airspan CWE-863
critical
10.0
2022-02-18 CVE-2022-21143 OS Command Injection vulnerability in Airspan products
MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does not properly sanitize user input on several locations, which may allow an attacker to inject arbitrary commands.
network
low complexity
airspan CWE-78
critical
10.0
2022-02-18 CVE-2022-21196 Unspecified vulnerability in Airspan products
MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does not perform proper authorization and authentication checks on multiple API routes.
network
low complexity
airspan
critical
9.8
2022-02-18 CVE-2022-21215 Server-Side Request Forgery (SSRF) vulnerability in Airspan products
This vulnerability could allow an attacker to force the server to create and execute a web request granting access to backend APIs that are only accessible to the Mimosa MMP server, or request pages that could perform some actions themselves.
network
low complexity
airspan CWE-918
critical
10.0
2008-03-10 CVE-2008-1262 Improper Authentication vulnerability in Airspan Wimax Prost 4.1
The administration panel on the Airspan WiMax ProST 4.1 antenna with 6.5.38.0 software does not verify authentication credentials, which allows remote attackers to (1) upload malformed firmware or (2) bind the antenna to a different WiMAX base station via unspecified requests to forms under process_adv/.
network
low complexity
airspan CWE-287
critical
10.0