High severity8.8NVD Advisory· Published Jan 6, 2023· Updated Jun 17, 2026
CVE-2022-44149
CVE-2022-44149
Description
The web service on Nexxt Amp300 ARN02304U8 42.103.1.5095 and 80.103.2.5045 devices allows remote OS command execution by placing &telnetd in the JSON host field to the ping feature of the goform/sysTools component. Authentication is required
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- Nexxt/Amp300description
- Range: 42.103.1.5095 and 80.103.2.5045
cpe:2.3:o:nexxtsolutions:amp300_firmware:42.103.1.5095:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:nexxtsolutions:amp300_firmware:42.103.1.5095:*:*:*:*:*:*:*
- cpe:2.3:o:nexxtsolutions:amp300_firmware:80.103.2.5045:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
5- packetstormsecurity.com/files/170366/Nexxt-Router-Firmware-42.103.1.5095-Remote-Code-Execution.htmlnvdExploitThird Party AdvisoryVDB Entry
- packetstormsecurity.com/files/170366/Nexxt-Router-Firmware-80.103.2.5045-Remote-Code-Execution.htmlnvdExploitThird Party AdvisoryVDB Entry
- cxsecurity.com/issue/WLB-2023010006nvdExploitThird Party Advisory
- packetstormsecurity.com/files/170366/Nexxt-Router-Firmware-42.103.1.5095-Remote-Code-Execution.htmlnvdExploitThird Party AdvisoryVDB Entry
- www.nexxtsolutions.com/connectivity/search/nvdProductVendor Advisory
News mentions
1- RondoDox: From Targeting Pwn2Own Vulnerabilities to Shotgunning ExploitsTrend Micro Research · Oct 9, 2025