Record summary

CVE-2023-3380 has a selected CVSS score of 4.7 (medium); EIP currently links 1 Nuclei template.

Description

A vulnerability classified as critical has been found in Wavlink WN579X3 up to 20230615. Affected is an unknown function of the file /cgi-bin/adm.cgi of the component Ping Test. The manipulation of the argument pingIp leads to injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-232236. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List20230615affected

Nuclei templates

1
ProjectDiscoveryCRITICALWAVLINK WN579X3 - Remote Command ExecutionCVSS 9.8

Remote Command Execution vulnerability in WAVLINK WN579X3 routers via pingIp parameter in /cgi-bin/adm.cgi.

Impact

Unauthenticated attackers can execute arbitrary commands through the pingIp parameter in the adm.cgi endpoint, potentially compromising the entire WAVLINK router and intercepting network traffic.

Remediation

Update WAVLINK WN579X3 firmware to a patched version that properly sanitizes the pingIp parameter and prevents command injection in adm.cgi.

WeaknessesCWE-74
Authorspussycat0x
Template tagscvecve2023wavlinkrcevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:o:wavlink:wn579x3_firmware:*:*:*:*:*:*:*:*
Shodan: http.html:"Wavlink"

Source: ProjectDiscovery

References

4