← Zuruck zu CVEs
CVE-2022-35518
CRITICAL9.8
Beschreibung
WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 nas.cgi has no filtering on parameters: User1Passwd and User1, which leads to command injection in page /nas_disk.shtml.
CVE Details
CVSS v3.1 Bewertung9.8
SchweregradCRITICAL
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht8/10/2022
Zuletzt geandert10/20/2025
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
wavlink:wn530h4wavlink:wn530h4_firmwarewavlink:wn531p3wavlink:wn531p3_firmwarewavlink:wn533a8wavlink:wn533a8_firmwarewavlink:wn535g3wavlink:wn535g3_firmwarewavlink:wn572hp3wavlink:wn572hp3_firmware
Schwachen (CWE)
CWE-77
Referenzen
https://github.com/TyeYeah/othercveinfo/blob/main/wavlink/README.md#wavlink-router-ac1200-page-nas_diskshtml-command-injection-in-nascgi(af854a3a-2127-422b-91ae-364da2661108)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.