CVE-2022-35534: Command Injection
WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 wireless.cgi has no filtering on parameter hiddenSSID32g and SSID2G2, which leads to command injection in page /wifimultissid.shtml.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-35534?
CVE-2022-35534 is a vulnerability found in WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, and WN531P3 routers that allows command injection.
How severe is CVE-2022-35534?
CVE-2022-35534 has a severity rating of 9.8 out of 10.
Which routers are affected by CVE-2022-35534?
WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, and WN531P3 routers are affected by CVE-2022-35534.
How can the CVE-2022-35534 vulnerability be exploited?
The CVE-2022-35534 vulnerability can be exploited through command injection in the /wifi_multi_ssid.shtml page of the router.
Is there a fix available for CVE-2022-35534?
At the moment, there is no information available about a fix for CVE-2022-35534. It is recommended to apply any security updates provided by the vendor and monitor for further updates.