CVE-2022-48165: High severity wavlink wl-wn530h4 firmware vulnerability
An access control issue in the component /cgi-bin/ExportLogs.sh of Wavlink WL-WN530H4 M30H4.V5030.210121 allows unauthenticated attackers to download configuration data and log files and obtain admin credentials.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-48165?
The severity of CVE-2022-48165 is high with a CVSS score of 7.5.
What is the affected software of CVE-2022-48165?
The affected software of CVE-2022-48165 is Wavlink WL-WN530H4 firmware version M30H4.V5030.210121.
What is the vulnerability description of CVE-2022-48165?
CVE-2022-48165 is an access control issue in the component /cgi-bin/ExportLogs.sh of Wavlink WL-WN530H4 firmware version M30H4.V5030.210121 that allows unauthenticated attackers to download configuration data and log files and obtain admin credentials.
How can an attacker exploit CVE-2022-48165?
An attacker can exploit CVE-2022-48165 by accessing the /cgi-bin/ExportLogs.sh component without authentication and downloading configuration data and log files, potentially obtaining admin credentials.
Is Wavlink WL-WN530H4 vulnerable to CVE-2022-48165?
No, Wavlink WL-WN530H4 itself is not vulnerable to CVE-2022-48165, but the firmware version M30H4.V5030.210121 is vulnerable.