Vulnerability record · CVE-2022-36266 · published 8 August 2022
CVE-2022-36266: Airspan airspot 5410 firmware cross-site scripting vulnerability
Airspan · Airspot 5410 Firmware
In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a stored XSS vulnerability. As the binary file /home/www/cgi-bin/login.cgi does not check if the user is authenticated, a malicious actor can craft a specific request on the login.cgi endpoint that contains a base32 encoded XSS payload that will be accepted and stored. A successful attack will results in the injection of malicious scripts into the user settings page.
Description
In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a stored XSS vulnerability. As the binary file /home/www/cgi-bin/login.cgi does not check if the user is authenticated, a malicious actor can craft a specific request on the login.cgi endpoint that contains a base32 encoded XSS payload that will be accepted and stored. A successful attack will results in the injection of malicious scripts into the user settings page.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/168114/FLIX-AX8-1.46.16-Remote-Command-Execution.html | Broken Link |
| https://gist.github.com/Nwqda/e82b3155401b094372195fdaa9b54833 | ExploitMitigationThird Party Advisory |
| https://wdi.rfwel.com/cdn/techdocs/AirSpot5410.pdf | ProductThird Party Advisory |
| http://packetstormsecurity.com/files/168114/FLIX-AX8-1.46.16-Remote-Command-Execution.html | Broken Link |
| https://gist.github.com/Nwqda/e82b3155401b094372195fdaa9b54833 | ExploitMitigationThird Party Advisory |
| https://wdi.rfwel.com/cdn/techdocs/AirSpot5410.pdf | ProductThird Party Advisory |
Track CVE-2022-36266 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-36266), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.