CVE-2022-35517: Command Injection
WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 adm.cgi has no filtering on parameters: webpskValue, wlMethod, wlanssid, EncrypType, rwanip, rwanmask, rwangateway, pppusername, ppppasswd and pppsetver, which leads to command injection in page /wizardroutermesh.shtml.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2022-35517.
What is the severity of CVE-2022-35517?
The severity of CVE-2022-35517 is high with a severity value of 8.8.
Which software is affected by CVE-2022-35517?
The following WAVLINK router models are affected by CVE-2022-35517: WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3.
What is the vulnerability description of CVE-2022-35517?
CVE-2022-35517 is a command injection vulnerability in the adm.cgi page of WAVLINK routers where certain parameters are not filtered, leading to potential command injection.
Is there a fix available for CVE-2022-35517?
At the time of writing, there is no official fix available for CVE-2022-35517. It is recommended to follow security best practices such as ensuring the router firmware is up to date, using strong passwords, and restricting remote access.