CVE-2022-34576: High severity wavlink wifi-repeater firmware vulnerability
Published Jul 25, 2022
·Updated
A vulnerability in /cgi-bin/ExportAllSettings.sh of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to execute arbitrary code via a crafted POST request.
Affected Software
2 affected components
Wavlink Wn535g3 Firmware=m35g3r.v5030.180927
Wavlink WN535G3
Event History
Jul 25, 2022
CVE Published
via MITRE·09:37 PM
Data Sourced
via MITRE·09:37 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this WAVLINK WN535 G3 firmware vulnerability?
The vulnerability ID is CVE-2022-34576.
2
What is the severity of CVE-2022-34576?
The severity of CVE-2022-34576 is high with a severity value of 7.5.
3
What is the affected software?
The affected software is the WAVLINK WN535 G3 firmware with version m35g3r.v5030.180927.
4
How can attackers exploit CVE-2022-34576?
Attackers can exploit CVE-2022-34576 by sending a crafted POST request to /cgi-bin/ExportAllSettings.sh.
5
Is there a fix for CVE-2022-34576?
A fix for CVE-2022-34576 may be provided by the vendor. It is recommended to update to the latest firmware version.