WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 login.cgi has no filtering on parameter key, which leads to command injection in page /login.shtml.
References
Link | Resource |
---|---|
https://github.com/TyeYeah/othercveinfo/blob/main/wavlink/README.md#wavlink-router-ac1200-page-loginshtml-command-injection-in-logincgi | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
History
08 Aug 2023, 14:21
Type | Values Removed | Values Added |
---|---|---|
CWE | NVD-CWE-Other |
15 Aug 2022, 12:44
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
CPE | cpe:2.3:h:wavlink:wn531p3:-:*:*:*:*:*:*:* cpe:2.3:h:wavlink:wn535g3:-:*:*:*:*:*:*:* cpe:2.3:o:wavlink:wn572hp3_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:wavlink:wn533a8:-:*:*:*:*:*:*:* cpe:2.3:h:wavlink:wn572hp3:-:*:*:*:*:*:*:* cpe:2.3:o:wavlink:wn535g3_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:wavlink:wn531p3_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:wavlink:wn530h4_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:wavlink:wn533a8_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:wavlink:wn530h4:-:*:*:*:*:*:*:* |
|
References | (MISC) https://github.com/TyeYeah/othercveinfo/blob/main/wavlink/README.md#wavlink-router-ac1200-page-loginshtml-command-injection-in-logincgi - Exploit, Third Party Advisory | |
CWE | CWE-77 |
10 Aug 2022, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-08-10 20:15
Updated : 2024-02-04 22:51
NVD link : CVE-2022-35526
Mitre link : CVE-2022-35526
CVE.ORG link : CVE-2022-35526
JSON object : View
Products Affected
wavlink
- wn531p3_firmware
- wn530h4_firmware
- wn535g3
- wn572hp3_firmware
- wn531p3
- wn530h4
- wn572hp3
- wn535g3_firmware
- wn533a8_firmware
- wn533a8
CWE