First published: Wed Aug 10 2022(Updated: )
WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 firewall.cgi has no filtering on parameters: remoteManagementEnabled, blockPortScanEnabled, pingFrmWANFilterEnabled and blockSynFloodEnabled, which leads to command injection in page /man_security.shtml.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Wavlink Wn572hp3 Firmware | ||
WAVLINK WN572HP3 | ||
Wavlink Wn533a8 Firmware | ||
Wavlink WN533A8 | ||
Wavlink Wn530h4 Firmware | ||
Wavlink WN530H4 | ||
Wavlink Wn535g3 Firmware | ||
Wavlink WN535G3 | ||
Wavlink Wn531p3 Firmware | ||
Wavlink Wn531p3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this WAVLINK firmware issue is CVE-2022-35521.
CVE-2022-35521 has a severity rating of 9.8 (critical).
The parameters affected in the firewall.cgi of WAVLINK routers are remoteManagementEnabled, blockPortScanEnabled, pingFrmWANFilterEnabled, and blockSynFloodEnabled.
The command injection in page /man_security.shtml can lead to unauthorized execution of commands on the router.
Currently, there is no information available about a fix for CVE-2022-35521. It is recommended to follow the provided reference link for updates and patches.