First published: Mon Sep 26 2022(Updated: )
Contec FXA3200 version 1.13.00 and under suffers from Insecure Permissions in the Wireless LAN Manager interface which allows malicious actors to execute Linux commands with root privilege via a hidden web page (/usr/www/ja/mnt_cmd.cgi).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Contec Fxa3000 Firmware | <=1.13.00 | |
Contec Fxa3000 Firmware | ||
Contec Fxa3020 | <=1.13.00 | |
Contec Fxa3020 Firmware | ||
Contec Fxa3200 Firmware | <=1.13.00 | |
Contec Fxa3200 Firmware | ||
Contec Fxa2000 | <1.39.00 | |
Contec Fxa2000 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-36158 is classified as a high severity vulnerability due to its potential for unauthorized command execution with root privileges.
To mitigate CVE-2022-36158, users should update the Contec FXA3200 firmware to a version higher than 1.13.00.
The vulnerable versions of the Contec FXA3200 firmware are 1.13.00 and earlier.
CVE-2022-36158 allows remote malicious actors to execute arbitrary Linux commands on the affected device with high privileges.
No, other devices like Contec FXA3000 and FXA3020 with firmware versions 1.13.00 and below are also affected.