CVE-2022-40623: WAVLINK Quantum D4G (WN531G3) CSRF
Published Sep 13, 2022
·Updated
The WAVLINK Quantum D4G (WN531G3) running firmware version M31G3.V5030.200325 does not utilize anti-CSRF tokens, which, when combined with other issues (such as CVE-2022-35518), can lead to remote, unauthenticated command execution.
Affected Software
4 affected components
Wavlink Wn531g3 Firmware<=m31g3.v5030.200325
Wavlink WN531G3
All of the following
Wavlink Wn531g3 Firmware<=m31g3.v5030.200325
Wavlink WN531G3
Event History
Sep 13, 2022
CVE Published
via MITRE·08:35 PM
Data Sourced
via MITRE·08:35 PM
DescriptionWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this WAVLINK Quantum D4G (WN531G3) firmware issue?
The vulnerability ID for this WAVLINK Quantum D4G (WN531G3) firmware issue is CVE-2022-40623.
2
What is the severity of CVE-2022-40623?
The severity of CVE-2022-40623 is high with a severity value of 8.8.
3
How does the vulnerability in WAVLINK Quantum D4G (WN531G3) firmware manifest?
The vulnerability in WAVLINK Quantum D4G (WN531G3) firmware allows for remote, unauthenticated command execution when combined with other issues.
4
What can happen if the WAVLINK Quantum D4G (WN531G3) firmware vulnerability is exploited?
Exploiting the vulnerability in WAVLINK Quantum D4G (WN531G3) firmware can lead to remote, unauthenticated command execution.
5
Is a fix available for CVE-2022-40623?
Unfortunately, the fix information is not available at this time.