← Back to browse · API

CVE-2022-21196

Severity
CRITICAL
CVSS
10.0
EPSS
0.03663
Risk score
41.28
CISA KEV
No
PoC
No
Published
2022-02-18
Modified
2025-04-16
First seen
2026-08-07
Aliases
EUVD-2022-26430, GHSA-VQJC-H5M3-4Q6J
Products
Airspan Networks:MMP unspecified <v1.0.3, Airspan Networks:PTMP C-series and A5x unspecified <v2.5.4.1, Airspan Networks:PTP C-series unspecified <v2.8.6.1
Sources
euvd EUVD-2022-26430

Description

MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does not perform proper authorization and authentication checks on multiple API routes. An attacker may gain access to these API routes and achieve remote code execution, create a denial-of-service condition, and obtain sensitive information.

References