Record summary

CVE-2022-34045 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

Wavlink WN530HG4 M30HG4.V5030.191116 was discovered to contain a hardcoded encryption/decryption key for its configuration files at /etc_ro/lighttpd/www/cgi-bin/ExportAllSettings.sh.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryCRITICALWAVLINK WN530HG4 - Improper Access ControlCVSS 9.8

WAVLINK WN530HG4 M30HG4.V5030.191116 is susceptible to improper access control. It contains a hardcoded encryption/decryption key for its configuration files at /etc_ro/lighttpd/www/cgi-bin/ExportAllSettings.sh. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized operations.

Impact

An attacker can exploit this vulnerability to gain unauthorized access to the router's settings and potentially compromise the network.

Remediation

Apply the latest firmware update provided by the vendor to fix the access control issue.

WeaknessesCWE-798
Authorsarafatansari
Template tagscvecve2022wavlinkexposurevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:o:wavlink:wl-wn530hg4_firmware:m30hg4.v5030.191116:*:*:*:*:*:*:*
Shodan: http.html:"WN530HG4"
Shodan: http.html:"wn530hg4"
Shodan: http.title:"wi-fi app login"
FOFA: body="wn530hg4"
FOFA: title="wi-fi app login"
Google: intitle:"wi-fi app login"

Source: ProjectDiscovery

References

2