CVE-2022-35524: Command Injection
WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 adm.cgi has no filtering on parameters: wlansignal, webpskValue, selEncrypTyp, selAutomode, wlanbssid, wlanssid and wlanchannel, which leads to command injection in page /wizardrep.shtml.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-35524?
CVE-2022-35524 is a vulnerability found in WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, and WN531P3 routers, specifically in the adm.cgi page, which allows for command injection.
What is the severity of CVE-2022-35524?
CVE-2022-35524 has a severity rating of 9.8 (critical).
Which software versions are affected by CVE-2022-35524?
WAVLINK WN572HP3 Firmware, WAVLINK WN533A8 Firmware, WAVLINK WN530H4 Firmware, WAVLINK WN535G3 Firmware, and WAVLINK WN531P3 Firmware are affected by CVE-2022-35524.
How can I fix CVE-2022-35524?
Currently, there is no known fix for CVE-2022-35524. It is recommended to contact the vendor for further assistance.
Where can I find more information about CVE-2022-35524?
More information about CVE-2022-35524 can be found at the following link: [link](https://github.com/TyeYeah/othercveinfo/blob/main/wavlink/README.md#wavlink-router-ac1200-page-wizard_repshtml-command-injection-in-admcgi)