CVE-2022-48166
Wavlink WL-WN530HG4 M30HG4.V5030.201217 - Information Disclosure
Record summary
CVE-2022-48166 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
An access control issue in Wavlink WL-WN530HG4 M30HG4.V5030.201217 allows unauthenticated attackers to download configuration data and log files and obtain admin credentials.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 25, 2025 · Source: CVE List
Nuclei templates
1ProjectDiscoveryHIGHWavlink WL-WN530HG4 M30HG4.V5030.201217 - Information DisclosureCVSS 7.5
An access control issue in Wavlink WL-WN530HG4 M30HG4.V5030.201217 allows unauthenticated attackers to download configuration data and log files and obtain admin credentials.
Impact
Successful exploitation could lead to sensitive information disclosure.
Remediation
Apply the latest firmware updates from Wavlink or implement network segmentation to restrict access to the device administration interface.
Source: ProjectDiscovery