Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Airspan

First CVE: Mar 10, 2008Active for: 18 yearsTotal CVEs: 21
50.2
VTI Score
TOP TARGET

Airspan manufactures wireless broadband and networking appliances, including point-to-point bridge and access point products such as the A5X and AirVelocity series, that serve as critical infrastructure in last-mile connectivity deployments. Its vulnerability footprint, though concentrated in a small product line, skews strongly toward critical-severity outcomes and frequently acquires public exploit tooling, reflecting the exposed network-facing role these devices occupy. The recurring weakness classes—improper authentication, cross-site scripting, OS command injection, and insufficiently protected credentials—cluster around input handling and access control in embedded web interfaces and firmware, which are characteristic attack surfaces for remotely accessible networking hardware. Defenders should treat Airspan appliances, particularly internet-exposed instances, as high-priority patching targets and inventory them carefully for credential management and firmware-update practices. Current exploitation activity, severity distributions, and exposure counts are shown alongside this summary.

FAUCET AI Generated
21
Total CVEs
More Total CVEs than 96% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 5% of tracked vendors
8.2
Avg CVSS Score
Higher Avg CVSS Score than 80% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Airspan over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 10, 2008
18 years ago
Most Recent CVE
Aug 16, 2022
1,439 days ago

Products(21 total)

Top CVEs

Signals from CVEs in this vendor scope (21 CVEs).

21 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-36267CRITICAL
In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Unauthenticated remote command injection vulnerability. The ping functionality can be called without user authent
Aug 8, 20229.872NOYES
CVE-2008-1262HIGH
The administration panel on the Airspan WiMax ProST 4.1 antenna with 6.5.38.0 software does not verify authentication credentials, which allows remote attackers to (1) upload malfo
Mar 10, 200810.041NOYES
CVE-2022-36309HIGH
Airspan AirVelocity 1500 software versions prior to 15.18.00.2511 have a root command injection vulnerability in the ActiveBank parameter of the recoverySubmit.cgi script running o
Aug 16, 20228.840NONO
CVE-2022-21141CRITICAL
MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does not perform proper authorizati
Feb 18, 20229.832NONO
CVE-2022-21196CRITICAL
MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does not perform proper authorizati
Feb 18, 20229.830NONO
CVE-2022-36308CRITICAL
Airspan AirVelocity 1500 web management UI displays SNMP credentials in plaintext on software versions older than 15.18.00.2511, and stores SNMPv3 credentials unhashed on the files
Aug 16, 20229.129NONO
CVE-2022-21215CRITICAL
This vulnerability could allow an attacker to force the server to create and execute a web request granting access to backend APIs that are only accessible to the Mimosa MMP server
Feb 18, 20229.829NONO
CVE-2022-21143CRITICAL
MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does not properly sanitize user inp
Feb 18, 20229.829NONO
CVE-2022-36310HIGH
Airspan AirVelocity 1500 software prior to version 15.18.00.2511 had NET-SNMP-EXTEND-MIB enabled on its snmpd service, enabling an attacker with SNMP write abilities to execute com
Aug 16, 20228.828NONO
CVE-2022-36264CRITICAL
In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists an Unauthenticated remote Arbitrary File Upload vulnerability which allows overwriting arbitrary files. A malicious
Aug 8, 20229.128NONO
View all 21 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products21 CVEs
24%
43%
33%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network17 (81.0%)
Unknown3 (14.3%)
Physical1 (4.8%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (85.7%)
High0 (0.0%)
Unknown3 (14.3%)
User Interaction
None15 (71.4%)
Unknown3 (14.3%)
Required3 (14.3%)
Privileges Required
Low4 (19.0%)
High1 (4.8%)
None13 (61.9%)
Unknown3 (14.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (21 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
9.5% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Airspan.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Airspan — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Airspan's Products

View all 3 CNAs →

Top CWEs