CVE-2022-35526: Command Injection
Published Aug 9, 2022
·Updated
WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 login.cgi has no filtering on parameter key, which leads to command injection in page /login.shtml.
Affected Software
10 affected components
Wavlink Wn572hp3 Firmware
Wavlink WN572HP3
Wavlink Wn533a8 Firmware
Wavlink WN533A8
Wavlink Wn530h4 Firmware
Wavlink WN530H4
Wavlink Wn535g3 Firmware
Wavlink WN535G3
Wavlink Wn531p3 Firmware
Wavlink WN531P3
Event History
Aug 9, 2022
CVE Published
via MITRE·07:43 PM
Data Sourced
via MITRE·07:43 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-35526.
2
What is the severity of CVE-2022-35526?
The severity of CVE-2022-35526 is critical with a CVSS score of 9.8.
3
Which software is affected by CVE-2022-35526?
The following WAVLINK devices are affected: WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3.
4
What is the vulnerability description of CVE-2022-35526?
CVE-2022-35526 is a command injection vulnerability in the login.cgi page of WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, and WN531P3 devices due to lack of filtering on parameter key.
5
Is there a fix available for CVE-2022-35526?
No information available about a fix for CVE-2022-35526.