{"api_version":"1","generated_at":"2026-07-23T22:21:49+00:00","cve":"CVE-2008-1262","urls":{"html":"https://cve.report/CVE-2008-1262","api":"https://cve.report/api/cve/CVE-2008-1262.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-1262","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-1262"},"summary":{"title":"CVE-2008-1262","description":"The administration panel on the Airspan WiMax ProST 4.1 antenna with 6.5.38.0 software does not verify authentication credentials, which allows remote attackers to (1) upload malformed firmware or (2) bind the antenna to a different WiMAX base station via unspecified requests to forms under process_adv/.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-03-10 17:44:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-287","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"10","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.vupen.com/english/advisories/2008/0802/references","name":"http://www.vupen.com/english/advisories/2008/0802/references","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/41052","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/41052","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.gnucitizen.org/projects/router-hacking-challenge/","name":"http://www.gnucitizen.org/projects/router-hacking-challenge/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Router Hacking Challenge | GNUCITIZEN","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://airspan4wimax.googlepages.com/","name":"http://airspan4wimax.googlepages.com/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"airspan4wimax - AirSpan WiMAX MicroMAX","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/29265","name":"http://secunia.com/advisories/29265","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Airspan WiMAX ProST Web Interface Authentication Bypass - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/28122","name":"http://www.securityfocus.com/bid/28122","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Airspan ProST WiMAX Device Web Interface Authentication Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.0x000000.com/?i=524","name":"http://www.0x000000.com/?i=524","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"H Tech Blog | Hack and Evolve Faster with the Common Techniques","mime":"text/html","httpstatus":"200","archivestatus":"403"},{"url":"http://www.securityfocus.com/archive/1/489009/100/0/threaded","name":"http://www.securityfocus.com/archive/1/489009/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.sharemethods.net/nepal/servlet/open?keeppath=false&aid=29820","name":"http://www.sharemethods.net/nepal/servlet/open?keeppath=false&aid=29820","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"ShareMethods Login","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.kb.cert.org/vuls/id/248372","name":"http://www.kb.cert.org/vuls/id/248372","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"US-CERT Vulnerability Note VU#248372","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-1262","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-1262","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"1262","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"airspan","cpe5":"wimax_prost","cpe6":"4.1","cpe7":"*","cpe8":"6.5.38.0","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T08:17:34.390Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20080301 The Router Hacking Challenge is Over!","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/489009/100/0/threaded"},{"name":"28122","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/28122"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.gnucitizen.org/projects/router-hacking-challenge/"},{"name":"wimaxprost-webinterface-security-bypass(41052)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/41052"},{"name":"VU#248372","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/248372"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.0x000000.com/?i=524"},{"name":"ADV-2008-0802","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2008/0802/references"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.sharemethods.net/nepal/servlet/open?keeppath=false&aid=29820"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://airspan4wimax.googlepages.com/"},{"name":"29265","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/29265"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-02-29T00:00:00.000Z","descriptions":[{"lang":"en","value":"The administration panel on the Airspan WiMax ProST 4.1 antenna with 6.5.38.0 software does not verify authentication credentials, which allows remote attackers to (1) upload malformed firmware or (2) bind the antenna to a different WiMAX base station via unspecified requests to forms under process_adv/."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-11T19:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20080301 The Router Hacking Challenge is Over!","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/489009/100/0/threaded"},{"name":"28122","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/28122"},{"tags":["x_refsource_MISC"],"url":"http://www.gnucitizen.org/projects/router-hacking-challenge/"},{"name":"wimaxprost-webinterface-security-bypass(41052)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/41052"},{"name":"VU#248372","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/248372"},{"tags":["x_refsource_MISC"],"url":"http://www.0x000000.com/?i=524"},{"name":"ADV-2008-0802","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2008/0802/references"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.sharemethods.net/nepal/servlet/open?keeppath=false&aid=29820"},{"tags":["x_refsource_MISC"],"url":"http://airspan4wimax.googlepages.com/"},{"name":"29265","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/29265"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-1262","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The administration panel on the Airspan WiMax ProST 4.1 antenna with 6.5.38.0 software does not verify authentication credentials, which allows remote attackers to (1) upload malformed firmware or (2) bind the antenna to a different WiMAX base station via unspecified requests to forms under process_adv/."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20080301 The Router Hacking Challenge is Over!","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/489009/100/0/threaded"},{"name":"28122","refsource":"BID","url":"http://www.securityfocus.com/bid/28122"},{"name":"http://www.gnucitizen.org/projects/router-hacking-challenge/","refsource":"MISC","url":"http://www.gnucitizen.org/projects/router-hacking-challenge/"},{"name":"wimaxprost-webinterface-security-bypass(41052)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/41052"},{"name":"VU#248372","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/248372"},{"name":"http://www.0x000000.com/?i=524","refsource":"MISC","url":"http://www.0x000000.com/?i=524"},{"name":"ADV-2008-0802","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2008/0802/references"},{"name":"http://www.sharemethods.net/nepal/servlet/open?keeppath=false&aid=29820","refsource":"CONFIRM","url":"http://www.sharemethods.net/nepal/servlet/open?keeppath=false&aid=29820"},{"name":"http://airspan4wimax.googlepages.com/","refsource":"MISC","url":"http://airspan4wimax.googlepages.com/"},{"name":"29265","refsource":"SECUNIA","url":"http://secunia.com/advisories/29265"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-1262","datePublished":"2008-03-10T17:00:00.000Z","dateReserved":"2008-03-10T00:00:00.000Z","dateUpdated":"2024-08-07T08:17:34.390Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-03-10 17:44:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-287","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:h:airspan:wimax_prost:4.1:*:6.5.38.0:*:*:*:*:*","matchCriteriaId":"B2D3669F-A37D-4286-A96D-829C54F45DA9"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"1262","Ordinal":"1","Title":"CVE-2008-1262","CVE":"CVE-2008-1262","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"1262","Ordinal":"1","NoteData":"The administration panel on the Airspan WiMax ProST 4.1 antenna with 6.5.38.0 software does not verify authentication credentials, which allows remote attackers to (1) upload malformed firmware or (2) bind the antenna to a different WiMAX base station via unspecified requests to forms under process_adv/.","Type":"Description","Title":"CVE-2008-1262"},{"CveYear":"2008","CveId":"1262","Ordinal":"2","NoteData":"2008-03-10","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"1262","Ordinal":"3","NoteData":"2018-10-11","Type":"Other","Title":"Modified"}]}}}