Vulnerability record · CVE-2022-32429 · published 10 August 2022
CVE-2022-32429: MSNSwitch firmware authentication bypass in ExportSettings.sh
Megatech · Msnswitch Firmware
The MSNSwitch MNT.2408 firmware exposes the ExportSettings.sh CGI endpoint without requiring authentication, allowing an attacker to change application settings. Because those settings can be abused to reach code execution, an unauthenticated network attacker can take over the device.
Description
An authentication-bypass issue in the component http://MYDEVICEIP/cgi-bin-sdb/ExportSettings.sh of Mega System Technologies Inc MSNSwitch MNT.2408 allows unauthenticated attackers to arbitrarily configure settings within the application, leading to remote code execution.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote code execution with a CVSS score of 9.8 and very high EPSS probability makes this an urgent exposure for any internet-facing device.
What it is
The MSNSwitch MNT.2408 firmware exposes the ExportSettings.sh CGI endpoint without requiring authentication, allowing an attacker to change application settings. Because those settings can be abused to reach code execution, an unauthenticated network attacker can take over the device.
Impact
An attacker gains full control of the device, including the ability to execute arbitrary code and alter its configuration. This can be used to pivot into the network the switch sits on.
Attack surface
The flaw is reached over the network via the HTTP endpoint /cgi-bin-sdb/ExportSettings.sh. No authentication or user interaction is required, as reflected by the CVSS vector AV:N/AC:L/PR:N/UI:N.
Exploitation
Public exploit code is referenced by Packet Storm and a third-party advisory, and EPSS is 0.756 (99.5th percentile), indicating a high likelihood of exploitation. The CVE is not listed in CISA KEV, so no confirmed in-the-wild activity is recorded here.
What to do
- Apply the vendor firmware update for MSNSwitch MNT.2408 if one is available; no fixed version is stated in this record.
- Restrict access to the device's web interface and CGI endpoints to trusted management networks only.
- Place the device behind a firewall or VPN and block direct internet exposure of port 80/443.
- Monitor the device for unexpected configuration changes and reflash or replace units that cannot be patched.
Detection
- Alert on HTTP requests to /cgi-bin-sdb/ExportSettings.sh from untrusted sources.
- Monitor for unexpected configuration changes or new administrative settings on MSNSwitch devices.
- Watch for outbound connections or process activity from the device consistent with command execution.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/169819/MSNSwitch-Firmware-MNT.2408-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://elifulkerson.com/CVE-2022-32429/ | ExploitThird Party Advisory |
| http://packetstormsecurity.com/files/169819/MSNSwitch-Firmware-MNT.2408-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://elifulkerson.com/CVE-2022-32429/ | ExploitThird Party Advisory |
Track CVE-2022-32429 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-32429), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.