CVE-2022-40621

HIGH

WAVLINK Quantum D4G - Info Disclosure

Title source: llm
STIX 2.1

Description

Because the WAVLINK Quantum D4G (WN531G3) running firmware version M31G3.V5030.200325 and earlier communicates over HTTP and not HTTPS, and because the hashing mechanism does not rely on a server-supplied key, it is possible for an attacker with sufficient network access to capture the hashed password of a logged on user and use it in a classic Pass-the-Hash style attack.

Scores

CVSS v3 7.5
EPSS 0.0031
EPSS Percentile 54.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-294
Status published
Products (1)
wavlink/wn531g3_firmware < m31g3.v5030.200325
Published Sep 13, 2022
Tracked Since Feb 18, 2026