CVE-2022-37149: OS Command Injection
WAVLINK WL-WN575A3 RPT75A3.V4300.201217 was discovered to contain a command injection vulnerability when operating the file adm.cgi. This vulnerability allows attackers to execute arbitrary commands via the username parameter.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this WAVLINK WL-WN575A3 firmware version?
The vulnerability ID for this WAVLINK WL-WN575A3 firmware version is CVE-2022-37149.
What is the severity of CVE-2022-37149?
The severity of CVE-2022-37149 is critical with a severity value of 9.8.
What is the description of CVE-2022-37149?
CVE-2022-37149 is a command injection vulnerability in the WAVLINK WL-WN575A3 firmware version RPT75A3.V4300.201217, specifically in the file adm.cgi. Attackers can exploit this vulnerability to execute arbitrary commands by manipulating the username parameter.
Which software is affected by CVE-2022-37149?
The WAVLINK WL-WN575A3 firmware version RPT75A3.V4300.201217 is affected by CVE-2022-37149.
How can I fix CVE-2022-37149?
There is currently no official fix or patch available for CVE-2022-37149. It is recommended to update to a newer, patched version of the firmware when it becomes available.