GatesAir Maxiva UAXT and VAXT Transmitter Remote Code Execution Vulnerability

Vulnerability

A critical remote code execution vulnerability has been identified in the web-based management interface of GatesAir Maxiva UAXT and VAXT transmitters, specifically when debugging mode is enabled. This vulnerability allows an attacker with a valid session ID to send specially crafted POST requests to the '/json' endpoint, executing arbitrary commands on the underlying system. The exploitation of this vulnerability could lead to full system compromise, including unauthorized access, privilege escalation, and complete device takeover.

Impact

Exploitation of this vulnerability allows for arbitrary command execution on the affected system, potentially leading to full system compromise and administrative access.

Reproduction

To reproduce this vulnerability, access the web-based management interface of a GatesAir Maxiva UAXT or VAXT transmitter with debugging mode enabled. Once in the interface, use a valid session ID to send POST requests to the '/json' endpoint, including the 'cmd' parameter with the desired command execution request. The server will execute the command on the underlying system, demonstrating the remote code execution vulnerability.

Remediation

To address this vulnerability, GatesAir should restrict access to debugging features and administrative endpoints, implement stronger authentication and session management, properly sanitize user inputs and commands, disable debugging mode in production environments, and conduct a comprehensive security audit of the management interface and backend system.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
6.6
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.