CVE-2022-36310
Airspan AirVelocity 1500 software prior to version 15.18.00.2511 had NET-SNMP-EXTEND-MIB enabled on its snmpd service, enabling an attacker with SNMP write abilities to execute commands as root on the eNodeB. This issue may affect other AirVelocity and AirSpeed models.
Scoring
- CVSS base score
- 0.04
- EPSS probability
- 0.95%
- CWE
- CWE-242
- Published
- 2022-08-16
- Last modified
- 2026-03-13
Affected products
- Airspan AirVelocity
Weakness type
Related vulnerabilities
- CVE-2026-11980 — Code execution in IBM Desktop App
- CVE-2026-6477 — PostgreSQL libpq lo_* functions let server superuser overwrite client stack memory
- CVE-2025-1994 — IBM Cognos Command Center code execution
- CVE-2025-49215 — A post-auth SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could...
- CVE-2025-1331 — IBM CICS TX code execution
- CVE-2024-52324 — Ruijie Reyee OS Use of Inherently Dangerous Function
- CVE-2021-40698 — ColdFusion Use of Inherently Dangerous Function Leads To Security feature bypass
- CVE-2021-42543 — AzeoTech DAQFactory