Record summary

CVE-2022-48165 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

An access control issue in the component /cgi-bin/ExportLogs.sh of Wavlink WL-WN530H4 M30H4.V5030.210121 allows unauthenticated attackers to download configuration data and log files and obtain admin credentials.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryHIGHWavlink - Improper Access ControlCVSS 7.5

Wavlink WL-WN530H4 M30H4.V5030.210121 is susceptible to improper access control in the component /cgi-bin/ExportLogs.sh. An attacker can download configuration data and log files, obtain admin credentials, and potentially execute unauthorized operations.

Impact

The vulnerability can lead to unauthorized access, data leakage, or unauthorized actions on the affected device.

Remediation

Apply the latest firmware update provided by the vendor to fix the access control issue.

WeaknessesCWE-284
AuthorsFor3stCo1d
Template tagscve2022cvewavlinkrouterexposurevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:o:wavlink:wl-wn530h4_firmware:m30h4.v5030.210121:*:*:*:*:*:*:*
Shodan: http.favicon.hash:-1350437236
FOFA: icon_hash=-1350437236

Source: ProjectDiscovery

References

3