CVE-2022-2488: WAVLINK WN535K2/WN535K3 touchlist_sync.cgi os command injection
Published Jul 20, 2022
·Updated
A vulnerability was found in WAVLINK WN535K2 and WN535K3 and classified as critical. This issue affects some unknown processing of the file /cgi-bin/touchlistsync.cgi. The manipulation of the argument IP leads to os command injection. The exploit has been disclosed to the public and may be used.
Affected Software
8 affected components
All of the following
Wavlink Wl-wn535k2 Firmware
Wavlink Wl-wn535k2
All of the following
Wavlink Wl-wn535k3 Firmware
Wavlink Wl-wn535k3
Wavlink Wl-wn535k2 Firmware
Wavlink Wl-wn535k2
Wavlink Wl-wn535k3 Firmware
Wavlink Wl-wn535k3
Event History
Jul 20, 2022
CVE Published
via MITRE·11:35 AM
Data Sourced
via MITRE·11:35 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID is CVE-2022-2488.
2
What is the severity of CVE-2022-2488?
The severity of CVE-2022-2488 is critical with a severity value of 9.8.
3
Which software versions are affected by CVE-2022-2488?
The WAVLINK WN535K2 and WN535K3 firmware versions are affected by CVE-2022-2488.
4
What is the impact of CVE-2022-2488?
CVE-2022-2488 allows for OS command injection, which can lead to unauthorized remote code execution.
5
How can I fix CVE-2022-2488?
Apply the latest firmware updates provided by WAVLINK to address CVE-2022-2488.