Record summary

CVE-2022-34576 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

A vulnerability in /cgi-bin/ExportAllSettings.sh of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to execute arbitrary code via a crafted POST request.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryHIGHWAVLINK WN535 G3 - Improper Access ControlCVSS 7.5

WAVLINK WN535 G3 M35G3R.V5030.180927 is susceptible to improper access control. A vulnerability in /cgi-bin/ExportAllSettings.sh allows an attacker to execute arbitrary code via a crafted POST request and thereby possibly obtain sensitive information, modify data, and/or execute unauthorized operations.

Impact

An attacker can exploit this vulnerability to gain unauthorized access to the router's settings and potentially compromise the network.

Remediation

Apply the latest firmware update provided by the vendor to fix the access control issue.

Authorsarafatansari
Template tagscvecve2022wavlinkexposurevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:o:wavlink:wn535g3_firmware:m35g3r.v5030.180927:*:*:*:*:*:*:*
Shodan: http.html:"Wavlink"
Shodan: http.html:"wavlink"
Shodan: http.title:"wi-fi app login"
FOFA: title="wi-fi app login"
FOFA: body="wavlink"
Google: intitle:"wi-fi app login"

Source: ProjectDiscovery

References

2