ZeroHour

CVE-2022-36158

PoC
CVSS 3.1
8.0 high
EPSS
2%p73
Published
()
Modified
Description

Contec FXA3200 version 1.13.00 and under suffers from Insecure Permissions in the Wireless LAN Manager interface which allows malicious actors to execute Linux commands with root privilege via a hidden web page (/usr/www/ja/mnt_cmd.cgi).

Vendors
contec
Products
fxa3000 firmware, fxa3020 firmware, fxa3200 firmware, fxa2000 firmware
Weakness
CWE-425
Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news