CVE-2022-40621: WAVLINK Quantum D4G (WN531G3) Pass-The-Hash
Because the WAVLINK Quantum D4G (WN531G3) running firmware version M31G3.V5030.200325 and earlier communicates over HTTP and not HTTPS, and because the hashing mechanism does not rely on a server-supplied key, it is possible for an attacker with sufficient network access to capture the hashed password of a logged on user and use it in a classic Pass-the-Hash style attack.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict network access to the WAVLINK Quantum D4G (WN531G3) so attackers cannot capture hashed credentials over HTTP and perform Pass-the-Hash.
Event History
Frequently Asked Questions
What is CVE-2022-40621?
CVE-2022-40621 is a vulnerability in the WAVLINK Quantum D4G (WN531G3) firmware that allows an attacker to capture hashed passwords due to the lack of HTTPS communication and a weak hashing mechanism.
How does CVE-2022-40621 impact the WAVLINK Quantum D4G (WN531G3)?
CVE-2022-40621 allows an attacker with sufficient network access to capture hashed passwords on the WAVLINK Quantum D4G (WN531G3) due to insecure HTTP communication and a weak hashing mechanism.
What is the severity of CVE-2022-40621?
CVE-2022-40621 has a severity rating of 7.5 (High).
What can an attacker do with captured hashed passwords from CVE-2022-40621?
An attacker can attempt to crack the captured hashed passwords to gain unauthorized access to user accounts and sensitive information.
How can I mitigate the CVE-2022-40621 vulnerability?
To mitigate CVE-2022-40621, ensure that the WAVLINK Quantum D4G (WN531G3) firmware is updated to version M31G3.V5030.200325 or later, and enable HTTPS communication to protect password hashes.