← Vulnerability feed

Vulnerability record · CVE-2022-36267 · published 8 August 2022

CVE-2022-36267: Airspan AirSpot 5410 diagnostics.cgi unauthenticated command injection

Airspan · Airspot 5410 Firmware

Airspan AirSpot 5410 firmware 0.3.4.1-4 and earlier exposes the diagnostics.cgi binary, which accepts unauthenticated HTTP requests and passes unsanitized parameter data into the ping functionality. An attacker can inject shell commands through that parameter and execute arbitrary code on the device. The flaw is remotely reachable with no credentials and no user interaction, making it a serious exposure for internet-facing units.

9.8 CVSS 3.1 Critical EPSS 55% · top 1.0%
9.8CVSS 3.1 base score
55%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Unauthenticated remote command injection vulnerability. The ping functionality can be called without user authentication when crafting a malicious http request by injecting code in one of the parameters allowing for remote code execution. This vulnerability is exploited via the binary file /home/www/cgi-bin/diagnostics.cgi that accepts unauthenticated requests and unsanitized data. As a result, a malicious actor can craft a specific request and interact remotely with the device.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

critical priorityUnauthenticated remote code execution with a 9.8 CVSS score, public exploit references and very high EPSS probability make this an urgent patch-or-isolate case.

What it is

Airspan AirSpot 5410 firmware 0.3.4.1-4 and earlier exposes the diagnostics.cgi binary, which accepts unauthenticated HTTP requests and passes unsanitized parameter data into the ping functionality. An attacker can inject shell commands through that parameter and execute arbitrary code on the device. The flaw is remotely reachable with no credentials and no user interaction, making it a serious exposure for internet-facing units.

Impact

An attacker gains remote code execution as the web server process on the AirSpot 5410, allowing full compromise of the device, including configuration changes, credential access and use of the device as a foothold into the connected network.

Attack surface

Reached over the network via HTTP requests to /home/www/cgi-bin/diagnostics.cgi; the ping functionality is callable without authentication and no user interaction is required. The CVSS vector confirms AV:N/AC:L/PR:N/UI:N.

Exploitation

Not listed in CISA KEV, but public exploit references exist (Packet Storm and a GitHub gist tagged Exploit) and EPSS is 0.54546 (98.9th percentile), indicating a high likelihood of exploitation activity. No ransomware group usage is documented.

What to do

  • Upgrade AirSpot 5410 firmware beyond 0.3.4.1-4 to a vendor-fixed release; if no fixed version is available, isolate or replace the device.
  • Remove or block external access to the management/diagnostics web interface; restrict it to a trusted management VLAN or VPN.
  • Block or filter requests to /cgi-bin/diagnostics.cgi at the reverse proxy or WAF, and disable the ping diagnostic feature if it is not required.
  • Monitor vendor advisories and the referenced mitigation gist for interim hardening guidance.
  • Rotate any credentials or keys stored on the device if compromise is suspected.

Detection

  • Inspect HTTP access logs for requests to /cgi-bin/diagnostics.cgi, especially with shell metacharacters (;, |, $(), backticks) in parameters.
  • Alert on unexpected outbound connections or processes spawned by the device's web server (e.g., ping, sh, wget, curl).
  • Monitor for configuration changes or new accounts on AirSpot 5410 devices outside change windows.
  • Use network monitoring to flag scanning or probing of the device's HTTP management port from untrusted sources.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-36267 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2022-36267), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.