CVE-2022-32429

An authentication-bypass issue in the component http://MYDEVICEIP/cgi-bin-sdb/ExportSettings.sh of Mega System Technologies Inc MSNSwitch MNT.2408 allows unauthenticated attackers to arbitrarily configure settings within the application, leading to remote code execution.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:megatech:msnswitch_firmware:mnt.2408:*:*:*:*:*:*:*
cpe:2.3:h:megatech:msnswitch:-:*:*:*:*:*:*:*

History

21 Nov 2024, 07:06

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/169819/MSNSwitch-Firmware-MNT.2408-Remote-Code-Execution.html - Exploit, Third Party Advisory, VDB Entry () http://packetstormsecurity.com/files/169819/MSNSwitch-Firmware-MNT.2408-Remote-Code-Execution.html - Exploit, Third Party Advisory, VDB Entry
References () https://elifulkerson.com/CVE-2022-32429/ - Exploit, Third Party Advisory () https://elifulkerson.com/CVE-2022-32429/ - Exploit, Third Party Advisory

Information

Published : 2022-08-10 20:15

Updated : 2024-11-21 07:06


NVD link : CVE-2022-32429

Mitre link : CVE-2022-32429

CVE.ORG link : CVE-2022-32429


JSON object : View

Products Affected

megatech

  • msnswitch
  • msnswitch_firmware
CWE
CWE-287

Improper Authentication