CVE-2023-3380

MEDIUM NUCLEI

WAVLINK WN579X3 - Remote Command Execution

Title source: nuclei
STIX 2.1

Exploitation Summary

CVE-2023-3380 has a Nuclei detection template available — see the Nuclei card below for the Shodan/FOFA recon queries.

Description

A vulnerability classified as critical has been found in Wavlink WN579X3 up to 20230615. Affected is an unknown function of the file /cgi-bin/adm.cgi of the component Ping Test. The manipulation of the argument pingIp leads to injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-232236. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Nuclei Templates (1)

WAVLINK WN579X3 - Remote Command Execution
CRITICALby pussycat0x
Shodan: http.html:"Wavlink"

References (3)

Core 3
Core References
Third Party Advisory vdb-entry technical-description
https://vuldb.com/?id.232236
Permissions Required, Third Party Advisory signature permissions-required
https://vuldb.com/?ctiid.232236

Scores

CVSS v3 4.7
EPSS 0.0361
EPSS Percentile 88.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L

Details

CWE
CWE-74
Status published
Products (1)
wavlink/wn579x3_firmware < 2023-06-15
Published Jun 23, 2023
Tracked Since Feb 18, 2026