Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
HighPublic exploit

Authenticated OS Command Injection in Nexxt Amp300 goform/sysTools ping feature

IdentifiersCVE-2022-44149CWE-78· Improper Neutralization of Special…

CVE-2022-44149 affects the web service on Nexxt Amp300 devices ARN02304U8 firmware versions 42.103.1.5095 and 80.103.2.5045. The vulnerability is in the goform/sysTools component's ping feature, which accepts JSON input and unsafely incorporates the host field into an operating-system command. An authenticated attacker can inject shell metacharacters and append commands by supplying a payload such as '&telnetd' in the JSON host parameter, resulting in remote OS command execution on the device.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation allows an authenticated remote attacker to execute arbitrary operating-system commands in the context of the vulnerable device's web service. This can be used to start services such as telnetd, deploy malware, alter device configuration, establish persistence, conscript the device into a botnet, or otherwise fully compromise the device's integrity and availability.

Mitigation

If you can’t patch tonight, do this now.

Restrict access to the device web management interface to trusted administrative networks only; do not expose it to the public internet. Disable remote administration if not required. Enforce strong unique credentials to reduce the chance of authenticated access. Segment affected devices from critical internal systems, monitor for unexpected process launches or services such as telnetd, and use network controls to limit management-plane access until patched firmware can be applied.

Remediation

Patch, then assume compromise.

Upgrade to a vendor-fixed firmware version if one is available from Nexxt. If no patched firmware is available, replace affected devices or remove them from exposed and sensitive environments. The vulnerable firmware versions specifically identified are 42.103.1.5095 and 80.103.2.5045, so remediation should include verifying installed firmware across the fleet and updating any affected Nexxt Amp300 ARN02304U8 devices.
PUBLIC EXPLOITS

Exploits

No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.

VALID 0 / 1 TOTALView more in app

All candidate exploits were filtered out by Mallory's validation.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
NexxtsolutionsAmp300 Firmwareoperating_system

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware1

Malware families riding this exploit, with evidence and IOCs.

Detection signatures1

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity

Community discussion across Reddit, Mastodon, and other social sources.