CVE-2022-48164: High severity wavlink wn533a8 firmware vulnerability
Published Feb 6, 2023
·Updated
An access control issue in the component /cgi-bin/ExportLogs.sh of Wavlink WL-WN533A8 M33A8.V5030.190716 allows unauthenticated attackers to download configuration data and log files and obtain admin credentials.
Affected Software
4 affected components
Wavlink Wl-wn533a8 Firmware=m33a8.v5030.190716
Wavlink WL-WN533A8
All of the following
Wavlink Wl-wn533a8 Firmware=m33a8.v5030.190716
Wavlink WL-WN533A8
Event History
Feb 6, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-48164.
2
What is the title of the vulnerability?
The title of the vulnerability is 'An access control issue in the component /cgi-bin/ExportLogs.sh of Wavlink WL-WN533A8 M33A8.V5030.190716'.
3
What is the severity of the vulnerability?
The severity of the vulnerability is high with a CVSS score of 7.5.
4
How does the vulnerability affect the Wavlink WL-WN533A8 firmware?
The vulnerability affects the Wavlink WL-WN533A8 firmware version M33A8.V5030.190716.
5
Is remote authentication required to exploit this vulnerability?
No, unauthenticated attackers can exploit this vulnerability.