CVE-2022-35536: Command Injection
WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 qos.cgi has no filtering on parameters: qosbandwith and qosdat, which leads to command injection in page /qos.shtml.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-35536.
What is the severity of CVE-2022-35536?
The severity of CVE-2022-35536 is critical with a severity value of 9.8.
Which software is affected by CVE-2022-35536?
The software affected by CVE-2022-35536 includes Wavlink WN572HP3 Firmware, Wavlink WN533A8 Firmware, Wavlink WN530H4 Firmware, Wavlink WN535G3 Firmware, and Wavlink WN531p3 Firmware.
What is the CWE category for CVE-2022-35536?
The CWE category for CVE-2022-35536 is CWE-77.
Where can I find more information about CVE-2022-35536?
You can find more information about CVE-2022-35536 at the following link: [GitHub - TyeYeah/othercveinfo](https://github.com/TyeYeah/othercveinfo/tree/main/wavlink#wavlink-router-ac1200-page-qosshtml-command-injection-in-qoscgi).