Vulnerability record · CVE-2022-36267 · published 8 August 2022
CVE-2022-36267: Airspan AirSpot 5410 diagnostics.cgi unauthenticated command injection
Airspan · Airspot 5410 Firmware
Airspan AirSpot 5410 firmware 0.3.4.1-4 and earlier exposes the diagnostics.cgi binary, which accepts unauthenticated HTTP requests and passes unsanitized parameter data into the ping functionality. An attacker can inject shell commands through that parameter and execute arbitrary code on the device. The flaw is remotely reachable with no credentials and no user interaction, making it a serious exposure for internet-facing units.
Description
In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Unauthenticated remote command injection vulnerability. The ping functionality can be called without user authentication when crafting a malicious http request by injecting code in one of the parameters allowing for remote code execution. This vulnerability is exploited via the binary file /home/www/cgi-bin/diagnostics.cgi that accepts unauthenticated requests and unsanitized data. As a result, a malicious actor can craft a specific request and interact remotely with the device.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote code execution with a 9.8 CVSS score, public exploit references and very high EPSS probability make this an urgent patch-or-isolate case.
What it is
Airspan AirSpot 5410 firmware 0.3.4.1-4 and earlier exposes the diagnostics.cgi binary, which accepts unauthenticated HTTP requests and passes unsanitized parameter data into the ping functionality. An attacker can inject shell commands through that parameter and execute arbitrary code on the device. The flaw is remotely reachable with no credentials and no user interaction, making it a serious exposure for internet-facing units.
Impact
An attacker gains remote code execution as the web server process on the AirSpot 5410, allowing full compromise of the device, including configuration changes, credential access and use of the device as a foothold into the connected network.
Attack surface
Reached over the network via HTTP requests to /home/www/cgi-bin/diagnostics.cgi; the ping functionality is callable without authentication and no user interaction is required. The CVSS vector confirms AV:N/AC:L/PR:N/UI:N.
Exploitation
Not listed in CISA KEV, but public exploit references exist (Packet Storm and a GitHub gist tagged Exploit) and EPSS is 0.54546 (98.9th percentile), indicating a high likelihood of exploitation activity. No ransomware group usage is documented.
What to do
- Upgrade AirSpot 5410 firmware beyond 0.3.4.1-4 to a vendor-fixed release; if no fixed version is available, isolate or replace the device.
- Remove or block external access to the management/diagnostics web interface; restrict it to a trusted management VLAN or VPN.
- Block or filter requests to /cgi-bin/diagnostics.cgi at the reverse proxy or WAF, and disable the ping diagnostic feature if it is not required.
- Monitor vendor advisories and the referenced mitigation gist for interim hardening guidance.
- Rotate any credentials or keys stored on the device if compromise is suspected.
Detection
- Inspect HTTP access logs for requests to /cgi-bin/diagnostics.cgi, especially with shell metacharacters (;, |, $(), backticks) in parameters.
- Alert on unexpected outbound connections or processes spawned by the device's web server (e.g., ping, sh, wget, curl).
- Monitor for configuration changes or new accounts on AirSpot 5410 devices outside change windows.
- Use network monitoring to flag scanning or probing of the device's HTTP management port from untrusted sources.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/168047/AirSpot-5410-0.3.4.1-4-Remote-Command-Injection.html | ExploitThird Party Advisory |
| https://gist.github.com/Nwqda/e82b3155401b094372195fdaa9b54833 | ExploitMitigationThird Party Advisory |
| https://wdi.rfwel.com/cdn/techdocs/AirSpot5410.pdf | ProductThird Party Advisory |
| http://packetstormsecurity.com/files/168047/AirSpot-5410-0.3.4.1-4-Remote-Command-Injection.html | ExploitThird Party Advisory |
| https://gist.github.com/Nwqda/e82b3155401b094372195fdaa9b54833 | ExploitMitigationThird Party Advisory |
| https://wdi.rfwel.com/cdn/techdocs/AirSpot5410.pdf | ProductThird Party Advisory |
Track CVE-2022-36267 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-36267), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.