CVE-2022-34576
WAVLINK WN535 G3 - Improper Access Control
Record summary
CVE-2022-34576 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
A vulnerability in /cgi-bin/ExportAllSettings.sh of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to execute arbitrary code via a crafted POST request.
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryHIGHWAVLINK WN535 G3 - Improper Access ControlCVSS 7.5
WAVLINK WN535 G3 M35G3R.V5030.180927 is susceptible to improper access control. A vulnerability in /cgi-bin/ExportAllSettings.sh allows an attacker to execute arbitrary code via a crafted POST request and thereby possibly obtain sensitive information, modify data, and/or execute unauthorized operations.
Impact
An attacker can exploit this vulnerability to gain unauthorized access to the router's settings and potentially compromise the network.
Remediation
Apply the latest firmware update provided by the vendor to fix the access control issue.
Source: ProjectDiscovery