peter bassill · operator
$ cve CVE-2022-21196 JSON

CVE-2022-21196

10.0
CRITICAL · CVSS 3.1 · EPSS 3.7% (pctl 89)

In your normal cycle

Critical by CVSS (10), but no sign of active exploitation.

Description

MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does not perform proper authorization and authentication checks on multiple API routes. An attacker may gain access to these API routes and achieve remote code execution, create a denial-of-service condition, and obtain sensitive information.

Scoring

CVSS10.0 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS3.66% — more likely to be exploited than 89% of all CVEs
WeaknessCWE-285
On CISA KEVno
Public exploitnone known
Published2022-02-18
Last modified2026-06-17

Affected (9)

VendorProduct
airspana5x
airspana5x firmware
airspanc5c
airspanc5c firmware
airspanc5x
airspanc5x firmware
airspanc6x
airspanc6x firmware
airspanmimosa management platform

References

→ the Explorer  ·  watch your stack  ·  NVD