CVE-2022-35518: Command Injection
WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 nas.cgi has no filtering on parameters: User1Passwd and User1, which leads to command injection in page /nasdisk.shtml.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-35518?
The severity of CVE-2022-35518 is critical, with a severity value of 9.8.
What is the affected software for CVE-2022-35518?
The affected software for CVE-2022-35518 includes WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3.
What is the vulnerability in WAVLINK routers?
The vulnerability in WAVLINK routers is a command injection in page /nas_disk.shtml, caused by the lack of filtering on parameters User1Passwd and User1 in nas.cgi.
How can I fix CVE-2022-35518?
To fix CVE-2022-35518, it is recommended to update the firmware of the affected WAVLINK routers to a version that includes the necessary security patches.
Where can I find more information about CVE-2022-35518?
More information about CVE-2022-35518 can be found at the following reference: [Link](https://github.com/TyeYeah/othercveinfo/blob/main/wavlink/README.md#wavlink-router-ac1200-page-nas_diskshtml-command-injection-in-nascgi)