CVE-2023-32622: OS Command Injection
Published Jun 30, 2023
·Updated
Improper neutralization of special elements in WL-WN531AX2 firmware versions prior to 2023526 allows an attacker with an administrative privilege to execute OS commands with the root privilege.
Affected Software
4 affected components
All of the following
Wavlink Wl-wn531ax2 Firmware<2023526
Wavlink Wl-wn531ax2
Wavlink Wl-wn531ax2 Firmware<2023526
Wavlink Wl-wn531ax2
Remediation
Patch Available
Event History
Jun 30, 2023
CVE Published
via MITRE·04:04 AM
Data Sourced
via MITRE·04:04 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-32622.
2
What is the severity level of CVE-2023-32622?
The severity level of CVE-2023-32622 is high (7.2).
3
What is the affected software for CVE-2023-32622?
The affected software for CVE-2023-32622 is Wavlink Wl-wn531ax2 firmware versions prior to 2023526.
4
How can an attacker exploit CVE-2023-32622?
An attacker with administrative privilege can exploit CVE-2023-32622 by executing OS commands with root privilege.
5
Are there any references for CVE-2023-32622?
Yes, you can find references for CVE-2023-32622 at the following links: [JVN](https://jvn.jp/en/jp/JVN78634340/) and [Wavlink](https://www.wavlink.com/en_us/firmware/details/932108ffc5.html).