CVE-2008-1262 EXPLOIT
10.0
HIGH · CVSS 2.0 · EPSS 8.5% (pctl 95)
Patch early
A public exploit exists.
Description
The administration panel on the Airspan WiMax ProST 4.1 antenna with 6.5.38.0 software does not verify authentication credentials, which allows remote attackers to (1) upload malformed firmware or (2) bind the antenna to a different WiMAX base station via unspecified requests to forms under process_adv/.
Scoring
| CVSS | 10.0 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 8.53% — more likely to be exploited than 95% of all CVEs |
| Weakness | CWE-287 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2008-03-10 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| airspan | wimax prost |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Airspan ProST WiMAX Device - Web Interface Authentication Bypass | 2008-03-06 |
References
- http://airspan4wimax.googlepages.com/
- http://secunia.com/advisories/29265
- http://www.0x000000.com/?i=524
- http://www.gnucitizen.org/projects/router-hacking-challenge/
- http://www.kb.cert.org/vuls/id/248372
- http://www.securityfocus.com/archive/1/489009/100/0/threaded
- http://www.securityfocus.com/bid/28122
- http://www.sharemethods.net/nepal/servlet/open?keeppath=false&aid=29820
- http://www.vupen.com/english/advisories/2008/0802/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41052
- http://airspan4wimax.googlepages.com/
- http://secunia.com/advisories/29265
- http://www.0x000000.com/?i=524
- http://www.gnucitizen.org/projects/router-hacking-challenge/
- http://www.kb.cert.org/vuls/id/248372
- http://www.securityfocus.com/archive/1/489009/100/0/threaded
- http://www.securityfocus.com/bid/28122
- http://www.sharemethods.net/nepal/servlet/open?keeppath=false&aid=29820
- http://www.vupen.com/english/advisories/2008/0802/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41052
→ the Explorer · watch your stack · NVD