WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 wireless.cgi has no filtering on parameter hiddenSSID32g and SSID2G2, which leads to command injection in page /wifi_multi_ssid.shtml.
References
Link | Resource |
---|---|
https://github.com/TyeYeah/othercveinfo/tree/main/wavlink#wavlink-router-ac1200-page-wifi_multi_ssidshtml-command-injection-in-wirelesscgi | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
History
08 Aug 2023, 14:21
Type | Values Removed | Values Added |
---|---|---|
CWE | NVD-CWE-Other |
15 Aug 2022, 12:33
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-77 | |
CPE | cpe:2.3:h:wavlink:wn531p3:-:*:*:*:*:*:*:* cpe:2.3:h:wavlink:wn535g3:-:*:*:*:*:*:*:* cpe:2.3:o:wavlink:wn572hp3_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:wavlink:wn533a8:-:*:*:*:*:*:*:* cpe:2.3:h:wavlink:wn572hp3:-:*:*:*:*:*:*:* cpe:2.3:o:wavlink:wn535g3_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:wavlink:wn531p3_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:wavlink:wn530h4_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:wavlink:wn533a8_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:wavlink:wn530h4:-:*:*:*:*:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
References | (MISC) https://github.com/TyeYeah/othercveinfo/tree/main/wavlink#wavlink-router-ac1200-page-wifi_multi_ssidshtml-command-injection-in-wirelesscgi - Exploit, Third Party Advisory |
10 Aug 2022, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-08-10 20:15
Updated : 2024-02-04 22:51
NVD link : CVE-2022-35534
Mitre link : CVE-2022-35534
CVE.ORG link : CVE-2022-35534
JSON object : View
Products Affected
wavlink
- wn531p3_firmware
- wn530h4_firmware
- wn535g3
- wn572hp3_firmware
- wn531p3
- wn530h4
- wn572hp3
- wn535g3_firmware
- wn533a8_firmware
- wn533a8
CWE