CVE-2022-36158
 
Severity Score
8.0
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Attend
*SSVC
Descriptions
Contec FXA3200 version 1.13.00 and under suffers from Insecure Permissions in the Wireless LAN Manager interface which allows malicious actors to execute Linux commands with root privilege via a hidden web page (/usr/www/ja/mnt_cmd.cgi).
Contec FXA3200 versiones 1.13.00 y anteriores, sufre de permisos no seguros en la interfaz del Wireless LAN Manager, lo que permite a actores maliciosos ejecutar comandos de Linux con privilegios de root por medio de una página web oculta (/usr/www/ja/mnt_cmd.cgi).
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Attend
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2022-07-18 CVE Reserved
- 2022-09-26 CVE Published
- 2025-03-30 EPSS Updated
- 2025-05-21 CVE Updated
- 2025-05-21 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-425: Direct Request ('Forced Browsing')
CAPEC
References (4)
URL | Date | SRC |
---|---|---|
https://samy.link/blog/contec-flexlan-fxa2000-and-fxa3000-series-vulnerability-repo | 2025-05-21 |
URL | Date | SRC |
---|---|---|
https://jvn.jp/en/vu/JVNVU98305100 | 2023-08-08 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Contec Search vendor "Contec" | Fxa3000 Firmware Search vendor "Contec" for product "Fxa3000 Firmware" | <= 1.13.00 Search vendor "Contec" for product "Fxa3000 Firmware" and version " <= 1.13.00" | - |
Affected
| in | Contec Search vendor "Contec" | Fxa3000 Search vendor "Contec" for product "Fxa3000" | - | - |
Safe
|
Contec Search vendor "Contec" | Fxa3020 Firmware Search vendor "Contec" for product "Fxa3020 Firmware" | <= 1.13.00 Search vendor "Contec" for product "Fxa3020 Firmware" and version " <= 1.13.00" | - |
Affected
| in | Contec Search vendor "Contec" | Fxa3020 Search vendor "Contec" for product "Fxa3020" | - | - |
Safe
|
Contec Search vendor "Contec" | Fxa3200 Firmware Search vendor "Contec" for product "Fxa3200 Firmware" | <= 1.13.00 Search vendor "Contec" for product "Fxa3200 Firmware" and version " <= 1.13.00" | - |
Affected
| in | Contec Search vendor "Contec" | Fxa3200 Search vendor "Contec" for product "Fxa3200" | - | - |
Safe
|
Contec Search vendor "Contec" | Fxa2000 Firmware Search vendor "Contec" for product "Fxa2000 Firmware" | < 1.39.00 Search vendor "Contec" for product "Fxa2000 Firmware" and version " < 1.39.00" | - |
Affected
| in | Contec Search vendor "Contec" | Fxa2000 Search vendor "Contec" for product "Fxa2000" | - | - |
Safe
|