CVE-2023-3380
Wavlink WN579X3 Ping Test adm.cgi injection
Record summary
CVE-2023-3380 has a selected CVSS score of 4.7 (medium); EIP currently links 1 Nuclei template.
Description
A vulnerability classified as critical has been found in Wavlink WN579X3 up to 20230615. Affected is an unknown function of the file /cgi-bin/adm.cgi of the component Ping Test. The manipulation of the argument pingIp leads to injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-232236. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
WN579X3Browse Wavlink / WN579X3 | CVE List | 20230615 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALWAVLINK WN579X3 - Remote Command ExecutionCVSS 9.8
Remote Command Execution vulnerability in WAVLINK WN579X3 routers via pingIp parameter in /cgi-bin/adm.cgi.
Impact
Unauthenticated attackers can execute arbitrary commands through the pingIp parameter in the adm.cgi endpoint, potentially compromising the entire WAVLINK router and intercepting network traffic.
Remediation
Update WAVLINK WN579X3 firmware to a patched version that properly sanitizes the pingIp parameter and prevents command injection in adm.cgi.
Source: ProjectDiscovery