CVE-2022-30489: XSS
Published May 13, 2022
·Updated
WAVLINK WN535 G3 was discovered to contain a cross-site scripting (XSS) vulnerability via the hostname parameter at /cgi-bin/login.cgi.
Affected Software
2 affected components
Wavlink Wn535g3 Firmware
Wavlink WN535G3
Event History
May 13, 2022
CVE Published
via MITRE·12:49 PM
Data Sourced
via MITRE·12:49 PM
Description
Frequently Asked Questions
1
What is CVE-2022-30489?
CVE-2022-30489 refers to a cross-site scripting (XSS) vulnerability in WAVLINK WN535 G3.
2
How does the vulnerability occur?
The vulnerability occurs when the hostname parameter is exploited in the /cgi-bin/login.cgi script of WAVLINK WN535 G3.
3
What is the severity of CVE-2022-30489?
CVE-2022-30489 has a severity rating of medium.
4
What is the affected software?
The affected software is the Wavlink Wn535g3 Firmware and the Wavlink WN535G3.
5
How can I fix CVE-2022-30489?
To fix CVE-2022-30489, it is recommended to update to the latest firmware version provided by WAVLINK.