In Airspan AirSpot 5410 version 0.3.4.1-4 and under there...
Critical severity
Unreviewed
Published
Aug 9, 2022
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Aug 8, 2022
Published to the GitHub Advisory Database
Aug 9, 2022
Last updated
Feb 1, 2023
In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists an Unauthenticated remote Arbitrary File Upload vulnerability which allows overwriting arbitrary files. A malicious actor can remotely upload a file of their choice and overwrite any file in the system by manipulating the filename and append a relative path that will be interpreted during the upload process. Using this method, it is possible to rewrite any file in the system or upload a new file.
References