CVE-2022-40622: WAVLINK Quantum D4G (WN531G3) Session Management by IP Address
The WAVLINK Quantum D4G (WN531G3) running firmware version M31G3.V5030.200325 uses IP addresses to hold sessions and does not not use session tokens. Therefore, if an attacker changes their IP address to match the logged-in administrator's, or is behind the same NAT as the logged in administrator, session takeover is possible.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Mitigate potential session takeover by IP by ensuring only the legitimate administrator can access the device management/web interface (e.g., restrict access via firewall/ACL to the admin’s IP and/or isolate the admin network so attackers cannot share the same NAT or IP range).
Event History
Frequently Asked Questions
What is CVE-2022-40622?
CVE-2022-40622 is a vulnerability found in the WAVLINK Quantum D4G (WN531G3) router firmware that allows an attacker to gain unauthorized access to the router by changing their IP address to match the logged-in administrator's or being behind the same NAT.
What is the severity of CVE-2022-40622?
CVE-2022-40622 has a severity score of 8.8, classified as high severity.
How does CVE-2022-40622 affect the WAVLINK Quantum D4G (WN531G3) firmware?
CVE-2022-40622 affects the WAVLINK Quantum D4G (WN531G3) firmware version M31G3.V5030.200325, making it vulnerable to unauthorized access.
How can an attacker exploit CVE-2022-40622?
An attacker can exploit CVE-2022-40622 by changing their IP address to match the logged-in administrator's or by being behind the same NAT.
Is the WAVLINK WN531G3 router vulnerable to CVE-2022-40622?
No, the WAVLINK WN531G3 router is not vulnerable to CVE-2022-40622.