Exploit Report

Computer Security And Bug Information

CVE-2022-36158

CVECVE-2022-36158
CVE Ordinal Value241861
Published Date2022-09-26T11:15Z
Modified Date2022-10-03T17:06Z
CWE TypeNVD-CWE-noinfo
CVSS 3.xCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
DescriptionContec FXA3200 version 1.13.00 and under suffers from Insecure Permissions in the Wireless LAN Manager interface which allows malicious actors to execute Linux commands with root privilege via a hidden web page (/usr/www/ja/mnt_cmd.cgi).
References
By clicking these links you will leave this website. We do not endorse and will not be held accountable for any activity on external sites.
Reference URLhttps://www.contec.com/products-services/computer-networking/flexlan-fx/fx-accesspoint/fxa3200/feature/#section
Reference DescriptionMISC https://www.contec.com/products-services/computer-networking/flexlan-fx/fx-accesspoint/fxa3200/feature/#section
Reference URLhttps://samy.link/blog/contec-flexlan-fxa2000-and-fxa3000-series-vulnerability-repo
Reference DescriptionMISC https://samy.link/blog/contec-flexlan-fxa2000-and-fxa3000-series-vulnerability-repo
Reference URLhttps://gist.github.com/Nwqda/aac33d1936d2b514a3268f145345abb4
Reference DescriptionMISC https://gist.github.com/Nwqda/aac33d1936d2b514a3268f145345abb4
Reference URLhttps://jvn.jp/en/vu/JVNVU98305100/
Reference DescriptionMISC https://jvn.jp/en/vu/JVNVU98305100/
TagsProduct
Sources NIST MITRE

This site's data is aggregated programmatically and provided "as is" without any representations or warranties, express or implied. Exploit.report is not affiliated with the The MITRE Corporation, U.S. Department of Homeland Security (DHS), Cybersecurity and Infrastructure Security Agency (CISA), or US government in any way. CVE and the CVE logo are registered trademarks of The MITRE Corporation

© 2022 Exploit.Report | Data | Contact | Privacy Policy | Articles