CVE-2022-36158 is an Insecure Permissions vulnerability affecting Contec FXA3200 (version 1.13.00 and older) and other FXA series devices. It allows authenticated attackers to execute Linux commands with root privileges through a hidden web page in the Wireless LAN Manager interface. With a CVSS score of 8.0 (HIGH), this vulnerability has an adjacent network attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. There is no evidence of active exploitation, nor is public exploit code available in Metasploit, Nuclei, or ExploitDB. However, there has been some community discussion and media coverage, including an article highlighting its potential impact on airplane Wi-Fi devices.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.13.00CPE matchmatch criteria | cpe:2.3:o:contec:fxa3000_firmware:*:*:*:*:*:*:*:* | ||
<= 1.13.00CPE matchmatch criteria | cpe:2.3:o:contec:fxa3020_firmware:*:*:*:*:*:*:*:* | ||
<= 1.13.00CPE matchmatch criteria | cpe:2.3:o:contec:fxa3200_firmware:*:*:*:*:*:*:*:* | ||
< 1.39.00CPE matchmatch criteria | cpe:2.3:o:contec:fxa2000_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.