Record summary

CVE-2022-30489 has a selected CVSS score of 6.1 (medium); EIP currently links 1 repository PoC and 1 Nuclei template.

Description

WAVLINK WN535 G3 was discovered to contain a cross-site scripting (XSS) vulnerability via the hostname parameter at /cgi-bin/login.cgi.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1
Nuclei templates
1

Proofs of concept

1

Repository PoCs

GitHubbadboycxcc/XSS-CVE-2022-30489Repository PoCby badboycxccStars: 2Not analyzed1 file

1.5 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMWavlink WN-535G3 - Cross-Site ScriptingCVSS 6.1

Wavlink WN-535G3 contains a POST cross-site scripting vulnerability via the hostname parameter at /cgi-bin/login.cgi.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the context of a victim's browser, potentially leading to session hijacking, defacement, or theft of sensitive information.

Remediation

Apply the latest firmware update provided by the vendor to mitigate this vulnerability.

WeaknessesCWE-79
AuthorsFor3stCo1d
Template tagscvecve2022xsswavlinkrouteriotvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:o:wavlink:wn535g3_firmware:-:*:*:*:*:*:*:*
Shodan: http.title:"Wi-Fi APP Login"
Shodan: http.html:"wavlink"
Shodan: http.title:"wi-fi app login"
FOFA: title="wi-fi app login"
FOFA: body="wavlink"
Google: intitle:"wi-fi app login"

Source: ProjectDiscovery

References

2