CVE-2022-30489
MEDIUMNuclei
Wavlink WN-535G3 - Cross-Site Scripting
Record summary
CVE-2022-30489 has a selected CVSS score of 6.1 (medium); EIP currently links 1 repository PoC and 1 Nuclei template.
Proofs of concept
1Repository PoCs
GitHubbadboycxcc/XSS-CVE-2022-30489Repository PoCby badboycxccStars: 2Not analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMWavlink WN-535G3 - Cross-Site ScriptingCVSS 6.1
Wavlink WN-535G3 contains a POST cross-site scripting vulnerability via the hostname parameter at /cgi-bin/login.cgi.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the context of a victim's browser, potentially leading to session hijacking, defacement, or theft of sensitive information.
Remediation
Apply the latest firmware update provided by the vendor to mitigate this vulnerability.
WeaknessesCWE-79
AuthorsFor3stCo1d
Template tagscvecve2022xsswavlinkrouteriotvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:o:wavlink:wn535g3_firmware:-:*:*:*:*:*:*:*
Shodan: http.title:"Wi-Fi APP Login"
Shodan: http.html:"wavlink"
Shodan: http.title:"wi-fi app login"
FOFA: title="wi-fi app login"
FOFA: body="wavlink"
Google: intitle:"wi-fi app login"
https://github.com/badboycxcc/XSS-CVE-2022-30489 https://github.com/badboycxcc/XSS https://nvd.nist.gov/vuln/detail/CVE-2022-30489 https://github.com/trhacknon/Pocingit https://github.com/trhacknon/XSS-CVE-2022-30489
Source: ProjectDiscovery
References
2github.com
https://github.com/badboycxcc/XSS nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-30489