CVE-2022-48164
wavlink wl-wn533a8_firmware Exposure of Sensitive Information to an Unauthorized Actor
Record summary
CVE-2022-48164 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
An access control issue in the component /cgi-bin/ExportLogs.sh of Wavlink WL-WN533A8 M33A8.V5030.190716 allows unauthenticated attackers to download configuration data and log files and obtain admin credentials.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · May 12, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 26, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
wl-wn533a8_firmwareBrowse wavlink / wl-wn533a8_firmware | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryHIGHWavlink WL-WN533A8 M33A8.V5030.190716 - Information DisclosureCVSS 7.5
An access control issue in the component /cgi-bin/ExportLogs.sh of Wavlink WL-WN533A8 M33A8.V5030.190716 allows unauthenticated attackers to download configuration data and log files and obtain admin credentials.
Impact
Successful exploitation could lead to sensitive information disclosure.
Remediation
Apply the latest firmware updates from Wavlink or implement network segmentation to restrict access to the device administration interface.
Source: ProjectDiscovery