Airspan manufactures wireless broadband and networking appliances, including point-to-point bridge and access point products such as the A5X and AirVelocity series, that serve as critical infrastructure in last-mile connectivity deployments. Its vulnerability footprint, though concentrated in a small product line, skews strongly toward critical-severity outcomes and frequently acquires public exploit tooling, reflecting the exposed network-facing role these devices occupy. The recurring weakness classes—improper authentication, cross-site scripting, OS command injection, and insufficiently protected credentials—cluster around input handling and access control in embedded web interfaces and firmware, which are characteristic attack surfaces for remotely accessible networking hardware. Defenders should treat Airspan appliances, particularly internet-exposed instances, as high-priority patching targets and inventory them carefully for credential management and firmware-update practices. Current exploitation activity, severity distributions, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Airspan over time
Signals from CVEs in this vendor scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-36267CRITICAL In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Unauthenticated remote command injection vulnerability. The ping functionality can be called without user authent | Aug 8, 2022 | 9.8 | 72 | NO | YES |
CVE-2008-1262HIGH The administration panel on the Airspan WiMax ProST 4.1 antenna with 6.5.38.0 software does not verify authentication credentials, which allows remote attackers to (1) upload malfo | Mar 10, 2008 | 10.0 | 41 | NO | YES |
CVE-2022-36309HIGH Airspan AirVelocity 1500 software versions prior to 15.18.00.2511 have a root command injection vulnerability in the ActiveBank parameter of the recoverySubmit.cgi script running o | Aug 16, 2022 | 8.8 | 40 | NO | NO |
CVE-2022-21141CRITICAL MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does not perform proper authorizati | Feb 18, 2022 | 9.8 | 32 | NO | NO |
CVE-2022-21196CRITICAL MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does not perform proper authorizati | Feb 18, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-36308CRITICAL Airspan AirVelocity 1500 web management UI displays SNMP credentials in plaintext on software versions older than 15.18.00.2511, and stores SNMPv3 credentials unhashed on the files | Aug 16, 2022 | 9.1 | 29 | NO | NO |
CVE-2022-21215CRITICAL This vulnerability could allow an attacker to force the server to create and execute a web request granting access to backend APIs that are only accessible to the Mimosa MMP server | Feb 18, 2022 | 9.8 | 29 | NO | NO |
CVE-2022-21143CRITICAL MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does not properly sanitize user inp | Feb 18, 2022 | 9.8 | 29 | NO | NO |
CVE-2022-36310HIGH Airspan AirVelocity 1500 software prior to version 15.18.00.2511 had NET-SNMP-EXTEND-MIB enabled on its snmpd service, enabling an attacker with SNMP write abilities to execute com | Aug 16, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-36264CRITICAL In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists an Unauthenticated remote Arbitrary File Upload vulnerability which allows overwriting arbitrary files. A malicious | Aug 8, 2022 | 9.1 | 28 | NO | NO |
Signals from CVEs in this vendor scope (21 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Airspan.
Media articles that mention a CVE ID that affects a product developed by Airspan — matched by CVE ID, not by vendor name.