{
	"CVE_data_meta": {
		"ASSIGNER": "cve-assign@fb.com",
		"DATE_ASSIGNED": "2022-07-19",
		"ID": "CVE-2022-36309",
		"STATE": "PUBLIC"
	},
	"affects": {
		"vendor": {
			"vendor_data": [
				{
					"vendor_name": "Airspan",
					"product": {
						"product_data": [
							{
								"product_name": "AirVelocity",
								"version": {
									"version_data": [
										{
											"version_affected": "<",
											"version_value": "15.18.00.2511"
										}
									]
								}
							}
						]
					}
				}
			]
		}
	},
	"data_format": "MITRE",
	"data_type": "CVE",
	"data_version": "4.0",
	"description": {
		"description_data": [
			{
				"lang": "eng",
				"value": "Airspan AirVelocity 1500 software versions prior to 15.18.00.2511 have a root command injection vulnerability in the ActiveBank parameter of the recoverySubmit.cgi script running on the eNodeB's web management UI. This issue may affect other AirVelocity and AirSpeed models."
			}
		]
	},
	"problemtype": {
		"problemtype_data": [
			{
				"description": [
					{
						"lang": "eng",
						"value": "CWE-78"
					}
				]
			}
		]
	},
	"references": {
		"reference_data": [
			{
				"refsource": "CONFIRM",
				"name": "https://helpdesk.airspan.com/browse/TRN3-1690",
				"url": "https://helpdesk.airspan.com/browse/TRN3-1690"
			},
			{
				"refsource": "MISC",
				"name": "https://github.com/metaredteam/external-disclosures/security/advisories/GHSA-p295-2jh6-g6g4",
				"url": "https://github.com/metaredteam/external-disclosures/security/advisories/GHSA-p295-2jh6-g6g4"
			}
		]
	}
}
