Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2022-44149
The web service on Nexxt Amp300 ARN02304U8 42.103.1.5095 and 80.103.2.5045 devices allows remote OS command execution by placing &telnetd in the JSON host field to the ping feature of the goform/sysTools component. Authentication is required
Exploit prediction scoring system (EPSS) score
EPSS Score
0.784
EPSS Ranking
99.0%
CVSS Severity
CVSS v3 Score
8.8
References
http://packetstormsecurity.com/files/170366/Nexxt-Router-Firmware-42.103.1.5095-Remote-Code-Execution.html
http://packetstormsecurity.com/files/170366/Nexxt-Router-Firmware-80.103.2.5045-Remote-Code-Execution.html
https://cxsecurity.com/issue/WLB-2023010006
https://packetstormsecurity.com/files/170366/Nexxt-Router-Firmware-42.103.1.5095-Remote-Code-Execution.html
https://www.nexxtsolutions.com/connectivity/search/?q=ARN02304U8
http://packetstormsecurity.com/files/170366/Nexxt-Router-Firmware-42.103.1.5095-Remote-Code-Execution.html
http://packetstormsecurity.com/files/170366/Nexxt-Router-Firmware-80.103.2.5045-Remote-Code-Execution.html
https://cxsecurity.com/issue/WLB-2023010006
https://packetstormsecurity.com/files/170366/Nexxt-Router-Firmware-42.103.1.5095-Remote-Code-Execution.html
https://www.nexxtsolutions.com/connectivity/search/?q=ARN02304U8
Products affected by CVE-2022-44149
Nexxtsolutions
»
Amp300
»
Version:
N/A
cpe:2.3:h:nexxtsolutions:amp300:-
Nexxtsolutions
»
Amp300 Firmware
»
Version:
42.103.1.5095
cpe:2.3:o:nexxtsolutions:amp300_firmware:42.103.1.5095
Nexxtsolutions
»
Amp300 Firmware
»
Version:
80.103.2.5045
cpe:2.3:o:nexxtsolutions:amp300_firmware:80.103.2.5045
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved