CVE-2022-21141: Airspan a5x Firmware

Critical severity, CVSS 9.8. EPSS: 3.2% chance of exploitation in the next 30 days.

MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does not perform proper authorization checks on multiple API functions. An attacker may gain access to these functions and achieve remote code execution, create a denial-of-service condition, and obtain sensitive information.

Affected products

  • Airspan a5x Firmware: before 2.5.4.1 (fixed in 2.5.4.1)
  • Airspan c5c Firmware: before 2.8.6.1 (fixed in 2.8.6.1)
  • Airspan c5x Firmware: before 2.8.6.1 (fixed in 2.8.6.1)
  • Airspan c6x Firmware: before 2.8.6.1 (fixed in 2.8.6.1)
  • Airspan Mimosa Management Platform: before 1.0.3 (fixed in 1.0.3)

Published 2022-02-18. Last modified 2026-06-17.