CVE-2022-32429

An authentication-bypass issue in the component http://MYDEVICEIP/cgi-bin-sdb/ExportSettings.sh of Mega System Technologies Inc MSNSwitch MNT.2408 allows unauthenticated attackers to arbitrarily configure settings within the application, leading to remote code execution.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:megatech:msnswitch_firmware:mnt.2408:*:*:*:*:*:*:*
cpe:2.3:h:megatech:msnswitch:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2022-08-10 20:15

Updated : 2022-12-08 22:34


NVD link : CVE-2022-32429

Mitre link : CVE-2022-32429

CVE.ORG link : CVE-2022-32429


JSON object : View

Products Affected

megatech

  • msnswitch
  • msnswitch_firmware
CWE
CWE-287

Improper Authentication