CVE-2022-35538: Command Injection
WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 wireless.cgi has no filtering on parameters: deletelist, deletealmac, bdeletelist and bdeletealmac, which leads to command injection in page /wifimesh.shtml.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-35538?
CVE-2022-35538 is a vulnerability in the WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, and WN531P3 routers, where the wireless.cgi page lacks parameter filtering, leading to command injection in the /wifi_mesh.shtml page.
How severe is CVE-2022-35538?
CVE-2022-35538 has a severity score of 9.8 (critical).
Which software versions are affected by CVE-2022-35538?
The Wavlink Wn572hp3, Wn533a8, Wn530h4, Wn535g3, and Wn531p3 routers with their respective firmware versions are affected.
What is the CWE classification for CVE-2022-35538?
CVE-2022-35538 is classified under CWE-77 (Improper Neutralization of Special Elements used in a Command ('Command Injection')).
How can I fix CVE-2022-35538?
To fix CVE-2022-35538, update your Wavlink router firmware to a version that includes the necessary filtering on parameters.