Share
## https://sploitus.com/exploit?id=3E19E75C-4847-5F17-B648-243F77F4F53F
# CVE-2022-32429
An authentication-bypass , MSNSwitch MNT.2408 allows unauthenticated attackers to arbitrarily configure settings within the application, leading to remote code execution.

POC for unauthenticated configuration dump, authenticated RCE on msnswitch firmware 2408.
 
Configuration dump only requires HTTP access.
Full RCE requires you to be on the same subnet as the device.