A critical remote code execution (RCE) vulnerability exists in the web-based management interface of GatesAir Maxiva UAXT, VAXT transmitters when debugging mode is enabled. An attacker with a valid session ID (sess_id) can send specially crafted POST requests to the /json endpoint, enabling arbitrary command execution on the underlying system. This vulnerability can lead to full system compromise, including unauthorized access, privilege escalation, and potentially full device takeover.
Metrics
Affected Vendors & Products
References
History
Fri, 14 Feb 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-77 | |
Metrics |
cvssV3_1
|
Thu, 13 Feb 2025 22:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A critical remote code execution (RCE) vulnerability exists in the web-based management interface of GatesAir Maxiva UAXT, VAXT transmitters when debugging mode is enabled. An attacker with a valid session ID (sess_id) can send specially crafted POST requests to the /json endpoint, enabling arbitrary command execution on the underlying system. This vulnerability can lead to full system compromise, including unauthorized access, privilege escalation, and potentially full device takeover. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-02-14T15:42:44.849Z
Reserved: 2025-01-09T00:00:00.000Z
Link: CVE-2025-22962

Updated: 2025-02-14T15:42:02.432Z

Status : Received
Published: 2025-02-13T23:15:11.140
Modified: 2025-02-14T16:15:34.803
Link: CVE-2025-22962

No data.