CVE-2022-35521: Command Injection
WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 firewall.cgi has no filtering on parameters: remoteManagementEnabled, blockPortScanEnabled, pingFrmWANFilterEnabled and blockSynFloodEnabled, which leads to command injection in page /mansecurity.shtml.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this WAVLINK firmware issue?
The vulnerability ID for this WAVLINK firmware issue is CVE-2022-35521.
What is the severity rating of CVE-2022-35521?
CVE-2022-35521 has a severity rating of 9.8 (critical).
Which parameters in the firewall.cgi of WAVLINK routers are affected?
The parameters affected in the firewall.cgi of WAVLINK routers are remoteManagementEnabled, blockPortScanEnabled, pingFrmWANFilterEnabled, and blockSynFloodEnabled.
What is the impact of the command injection in page /man_security.shtml?
The command injection in page /man_security.shtml can lead to unauthorized execution of commands on the router.
Is there a fix available for CVE-2022-35521?
Currently, there is no information available about a fix for CVE-2022-35521. It is recommended to follow the provided reference link for updates and patches.