Record summary

CVE-2022-48164 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

An access control issue in the component /cgi-bin/ExportLogs.sh of Wavlink WL-WN533A8 M33A8.V5030.190716 allows unauthenticated attackers to download configuration data and log files and obtain admin credentials.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · May 12, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 26, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryHIGHWavlink WL-WN533A8 M33A8.V5030.190716 - Information DisclosureCVSS 7.5

An access control issue in the component /cgi-bin/ExportLogs.sh of Wavlink WL-WN533A8 M33A8.V5030.190716 allows unauthenticated attackers to download configuration data and log files and obtain admin credentials.

Impact

Successful exploitation could lead to sensitive information disclosure.

Remediation

Apply the latest firmware updates from Wavlink or implement network segmentation to restrict access to the device administration interface.

Authorsritikchaddha
Template tagscvecve2022wavlinkexposurewn533a8vkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:o:wavlink:wl-wn533a8_firmware:m33a8.v5030.190716:*:*:*:*:*:*:*
Shodan: html:"WN533A8"
FOFA: body="WN533A8"

Source: ProjectDiscovery

References

3