CVE-2022-48165
Wavlink - Improper Access Control
Record summary
CVE-2022-48165 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
An access control issue in the component /cgi-bin/ExportLogs.sh of Wavlink WL-WN530H4 M30H4.V5030.210121 allows unauthenticated attackers to download configuration data and log files and obtain admin credentials.
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryHIGHWavlink - Improper Access ControlCVSS 7.5
Wavlink WL-WN530H4 M30H4.V5030.210121 is susceptible to improper access control in the component /cgi-bin/ExportLogs.sh. An attacker can download configuration data and log files, obtain admin credentials, and potentially execute unauthorized operations.
Impact
The vulnerability can lead to unauthorized access, data leakage, or unauthorized actions on the affected device.
Remediation
Apply the latest firmware update provided by the vendor to fix the access control issue.
Source: ProjectDiscovery