airspan records
21 published records for vendor airspan.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 4
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-255 Credentials Management Errors2
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-285 Improper Authorization1
- CWE-287 Improper Authentication1
- CWE-327 Use of a Broken or Risky Cryptographic Algorithm1
The weakness classes this vendor ships most often: where to look.
CWEAll records
21 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
55Plan | CVE-2022-36267Proof of concept | In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Unauthenticated remote command injection vulnerability.airspan · airspot 5410 firmware | Critical9.8 | — | 54.5% | Aug 8, 2022 |
43Plan | CVE-2008-1262Proof of concept | The administration panel on the Airspan WiMax ProST 4.1 antenna with 6.5.38.0 software does not verify authentication credentials, which allairspan · wimax prost · CWE-287 | Critical10.0 | — | 8.5% | Mar 10, 2008 |
42Plan | CVE-2022-36309No exploit | Airspan AirVelocity 1500 software versions prior to 15.18.00.2511 have a root command injection vulnerability in the ActiveBank parameter ofairspan · airvelocity 1500 firmware · CWE-78 | High8.8 | — | 24.6% | Aug 15, 2022 |
40Plan | CVE-2022-21196No exploit | Airspan Networks Mimosa Improper Authorizationairspan · mimosa management platform · CWE-285 | Critical9.8 | — | 3.7% | Feb 18, 2022 |
40Plan | CVE-2022-21141No exploit | Airspan Networks Mimosa Incorrect Authorizationairspan · mimosa management platform · CWE-863 | Critical9.8 | — | 3.2% | Feb 18, 2022 |
39Monitor | CVE-2022-21215No exploit | Airspan Networks Mimosa Server-Side Request Forgery (SSRF)airspan · mimosa management platform · CWE-918 | Critical9.8 | — | 1.4% | Feb 18, 2022 |
39Monitor | CVE-2022-21143No exploit | Airspan Networks Mimosa OS Command Injectionairspan · mimosa management platform · CWE-78 | Critical9.8 | — | 1.2% | Feb 18, 2022 |
36Monitor | CVE-2022-36264No exploit | In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists an Unauthenticated remote Arbitrary File Upload vulnerability which allows airspan · airspot 5410 firmware · CWE-434 | Critical9.1 | — | 1.6% | Aug 8, 2022 |
36Monitor | CVE-2022-36308No exploit | Airspan AirVelocity 1500 web management UI displays SNMP credentials in plaintext on software versions older than 15.18.00.2511, and stores airspan · airvelocity 1500 firmware · CWE-256 | Critical9.1 | — | 0.7% | Aug 15, 2022 |
35Monitor | CVE-2022-36310No exploit | Airspan AirVelocity 1500 software prior to version 15.18.00.2511 had NET-SNMP-EXTEND-MIB enabled on its snmpd service, enabling an attacker airspan · airvelocity 1500 firmware · CWE-242 | High8.8 | — | 1.5% | Aug 15, 2022 |
35Monitor | CVE-2022-36312No exploit | Airspan AirVelocity 1500 software version 15.18.00.2511 lacks CSRF protections in the eNodeB's web management UI.airspan · airvelocity 1500 firmware · CWE-352 | High8.8 | — | 0.3% | Aug 15, 2022 |
31Monitor | CVE-2008-1542No exploit | Airspan Base Station Distribution Unit (BSDU) has "topsecret" as its password for the root account, which allows remote attackers to obtain airspan · base station distribution unit · CWE-255 | High7.5 | — | 1.8% | Mar 28, 2008 |
30Monitor | CVE-2008-1543No exploit | The Advanced User Interface Pages in the ProST Web Management component on the Airspan WiMAX ProST have a certain default User ID and passwoairspan · easy st · CWE-255 | High7.5 | — | 1.2% | Mar 28, 2008 |
30Monitor | CVE-2022-21176No exploit | Airspan Networks Mimosa SQL Injectionairspan · mimosa management platform · CWE-89 | High7.5 | — | 1.1% | Feb 18, 2022 |
30Monitor | CVE-2022-0138No exploit | Airspan Networks Mimosa Deserialization of Untrusted Dataairspan · mimosa management platform · CWE-502 | High7.5 | — | 1.0% | Feb 18, 2022 |
28Monitor | CVE-2022-36265No exploit | In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Hidden system command web page.airspan · airspot 5410 firmware | High7.2 | — | 1.4% | Aug 8, 2022 |
27Monitor | CVE-2022-36307No exploit | The AirVelocity 1500 prints SNMP credentials on its physically accessible serial port during boot.airspan · airvelocity 1500 firmware · CWE-522 | Medium6.8 | — | 0.3% | Aug 15, 2022 |
26Monitor | CVE-2022-36306No exploit | An authenticated attacker can enumerate and download sensitive files, including the eNodeB's web management UI's TLS private key, the web seairspan · airvelocity 1500 firmware · CWE-219 | Medium6.5 | — | 1.0% | Aug 15, 2022 |
26Monitor | CVE-2022-21800No exploit | Airspan Networks Mimosa Use of a Broken or Risky Cryptographic Algorithmairspan · mimosa management platform · CWE-327 | Medium6.5 | — | 0.5% | Feb 18, 2022 |
24Monitor | CVE-2022-36266No exploit | In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a stored XSS vulnerability.airspan · airspot 5410 firmware · CWE-79 | Medium6.1 | — | 1.0% | Aug 8, 2022 |
24Monitor | CVE-2022-36311No exploit | Airspan AirVelocity 1500 prior to software version 15.18.00.2511 is vulnerable to injection leading to XSS in the SNMP community field in thairspan · airvelocity 1500 firmware · CWE-79 | Medium6.1 | — | 0.4% | Aug 15, 2022 |
- CVE-2022-3626755Plan
In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Unauthenticated remote command injection vulnerability.
CriticalCVSS 9.8Proof of conceptEPSS 55%airspan · airspot 5410 firmwareAug 8, 2022
- CVE-2008-126243Plan
The administration panel on the Airspan WiMax ProST 4.1 antenna with 6.5.38.0 software does not verify authentication credentials, which all
CriticalCVSS 10.0Proof of conceptEPSS 9%airspan · wimax prostMar 10, 2008
- CVE-2022-3630942Plan
Airspan AirVelocity 1500 software versions prior to 15.18.00.2511 have a root command injection vulnerability in the ActiveBank parameter of
HighCVSS 8.8No exploitEPSS 25%airspan · airvelocity 1500 firmwareAug 15, 2022
- CVE-2022-2119640Plan
Airspan Networks Mimosa Improper Authorization
CriticalCVSS 9.8No exploitEPSS 4%airspan · mimosa management platformFeb 18, 2022
- CVE-2022-2114140Plan
Airspan Networks Mimosa Incorrect Authorization
CriticalCVSS 9.8No exploitEPSS 3%airspan · mimosa management platformFeb 18, 2022
- CVE-2022-2121539Monitor
Airspan Networks Mimosa Server-Side Request Forgery (SSRF)
CriticalCVSS 9.8No exploitEPSS 1%airspan · mimosa management platformFeb 18, 2022
- CVE-2022-2114339Monitor
Airspan Networks Mimosa OS Command Injection
CriticalCVSS 9.8No exploitEPSS 1%airspan · mimosa management platformFeb 18, 2022
- CVE-2022-3626436Monitor
In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists an Unauthenticated remote Arbitrary File Upload vulnerability which allows
CriticalCVSS 9.1No exploitEPSS 2%airspan · airspot 5410 firmwareAug 8, 2022
- CVE-2022-3630836Monitor
Airspan AirVelocity 1500 web management UI displays SNMP credentials in plaintext on software versions older than 15.18.00.2511, and stores
CriticalCVSS 9.1No exploitEPSS 1%airspan · airvelocity 1500 firmwareAug 15, 2022
- CVE-2022-3631035Monitor
Airspan AirVelocity 1500 software prior to version 15.18.00.2511 had NET-SNMP-EXTEND-MIB enabled on its snmpd service, enabling an attacker
HighCVSS 8.8No exploitEPSS 2%airspan · airvelocity 1500 firmwareAug 15, 2022
- CVE-2022-3631235Monitor
Airspan AirVelocity 1500 software version 15.18.00.2511 lacks CSRF protections in the eNodeB's web management UI.
HighCVSS 8.8No exploitEPSS 0%airspan · airvelocity 1500 firmwareAug 15, 2022
- CVE-2008-154231Monitor
Airspan Base Station Distribution Unit (BSDU) has "topsecret" as its password for the root account, which allows remote attackers to obtain
HighCVSS 7.5No exploitEPSS 2%airspan · base station distribution unitMar 28, 2008
- CVE-2008-154330Monitor
The Advanced User Interface Pages in the ProST Web Management component on the Airspan WiMAX ProST have a certain default User ID and passwo
HighCVSS 7.5No exploitEPSS 1%airspan · easy stMar 28, 2008
- CVE-2022-2117630Monitor
Airspan Networks Mimosa SQL Injection
HighCVSS 7.5No exploitEPSS 1%airspan · mimosa management platformFeb 18, 2022
- CVE-2022-013830Monitor
Airspan Networks Mimosa Deserialization of Untrusted Data
HighCVSS 7.5No exploitEPSS 1%airspan · mimosa management platformFeb 18, 2022
- CVE-2022-3626528Monitor
In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Hidden system command web page.
HighCVSS 7.2No exploitEPSS 1%airspan · airspot 5410 firmwareAug 8, 2022
- CVE-2022-3630727Monitor
The AirVelocity 1500 prints SNMP credentials on its physically accessible serial port during boot.
MediumCVSS 6.8No exploitEPSS 0%airspan · airvelocity 1500 firmwareAug 15, 2022
- CVE-2022-3630626Monitor
An authenticated attacker can enumerate and download sensitive files, including the eNodeB's web management UI's TLS private key, the web se
MediumCVSS 6.5No exploitEPSS 1%airspan · airvelocity 1500 firmwareAug 15, 2022
- CVE-2022-2180026Monitor
Airspan Networks Mimosa Use of a Broken or Risky Cryptographic Algorithm
MediumCVSS 6.5No exploitEPSS 1%airspan · mimosa management platformFeb 18, 2022
- CVE-2022-3626624Monitor
In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a stored XSS vulnerability.
MediumCVSS 6.1No exploitEPSS 1%airspan · airspot 5410 firmwareAug 8, 2022
- CVE-2022-3631124Monitor
Airspan AirVelocity 1500 prior to software version 15.18.00.2511 is vulnerable to injection leading to XSS in the SNMP community field in th
MediumCVSS 6.1No exploitEPSS 0%airspan · airvelocity 1500 firmwareAug 15, 2022