Record summary

CVE-2022-48166 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

An access control issue in Wavlink WL-WN530HG4 M30HG4.V5030.201217 allows unauthenticated attackers to download configuration data and log files and obtain admin credentials.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 25, 2025 · Source: CVE List

Nuclei templates

1
ProjectDiscoveryHIGHWavlink WL-WN530HG4 M30HG4.V5030.201217 - Information DisclosureCVSS 7.5

An access control issue in Wavlink WL-WN530HG4 M30HG4.V5030.201217 allows unauthenticated attackers to download configuration data and log files and obtain admin credentials.

Impact

Successful exploitation could lead to sensitive information disclosure.

Remediation

Apply the latest firmware updates from Wavlink or implement network segmentation to restrict access to the device administration interface.

Authorsritikchaddha
Template tagscvecve2022wavlinkexposurewn530hg4vuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:o:wavlink:wl-wn530hg4_firmware:m30hg4.v5030.201217:*:*:*:*:*:*:*
Shodan: html:"WN530HG4"
FOFA: body="WN530HG4"

Source: ProjectDiscovery

References

3