Security Advisory
CVE-2022-36309
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
Airspan AirVelocity 1500 software versions prior to 15.18.00.2511 have a root command injection vulnerability in the ActiveBank parameter of the recoverySubmit.cgi script running on the eNodeBs web management UI. This issue may affect other AirVelocity and AirSpeed models.