2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2022-35522" ,
"sourceIdentifier" : "cve@mitre.org" ,
"published" : "2022-08-10T20:15:55.717" ,
2024-04-04 08:46:00 +00:00
"lastModified" : "2023-08-08T14:21:49.707" ,
2023-04-24 12:24:31 +02:00
"vulnStatus" : "Analyzed" ,
"descriptions" : [
{
"lang" : "en" ,
"value" : "WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 adm.cgi has no filtering on parameters: ppp_username, ppp_passwd, rwan_gateway, rwan_mask and rwan_ip, which leads to command injection in page /wan.shtml."
} ,
{
"lang" : "es" ,
"value" : "WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3, el archivo adm.cgi no presenta ning\u00fan filtro en los par\u00e1metros: ppp_username, ppp_passwd, rwan_gateway, rwan_mask y rwan_ip, lo que conlleva a una inyecci\u00f3n de comandos en la p\u00e1gina /wan.shtml"
}
] ,
"metrics" : {
"cvssMetricV31" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
"availabilityImpact" : "HIGH" ,
"baseScore" : 9.8 ,
"baseSeverity" : "CRITICAL"
} ,
"exploitabilityScore" : 3.9 ,
"impactScore" : 5.9
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
2024-04-04 08:46:00 +00:00
"value" : "NVD-CWE-Other"
2023-04-24 12:24:31 +02:00
}
]
}
] ,
"configurations" : [
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:wavlink:wn572hp3_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "0C10B4A3-06B7-4D00-B19D-33AA1BA0B4F7"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:wavlink:wn572hp3:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "EF8FDD60-72C0-4B79-A34E-2D421C148D1D"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:wavlink:wn533a8_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "933A1BB4-577C-442D-8357-2EC7CE5E712F"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:wavlink:wn533a8:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "45611095-CAF7-40B2-BDA8-B1483B4329FF"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:wavlink:wn530h4_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "4EEDA6D9-FD39-4123-BDF8-ED1D9C135993"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:wavlink:wn530h4:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "3EA1D9AB-9DD2-42A8-BE96-6A07CB232C48"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:wavlink:wn535g3_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "C4E9A604-7475-4035-B116-A739A4FA6371"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:wavlink:wn535g3:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "B8F9E9ED-DDDC-4E7D-8179-F497AFD5EF97"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:wavlink:wn531p3_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8BCB68D6-1392-4C63-ABDE-D5BE2E44A4BE"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:wavlink:wn531p3:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "2049DBB6-8443-447E-A537-B8F44F533324"
}
]
}
]
}
] ,
"references" : [
{
"url" : "https://github.com/TyeYeah/othercveinfo/blob/main/wavlink/README.md#wavlink-router-ac1200-page-wanshtml-command-injection-in-admcgi" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Exploit" ,
"Third Party Advisory"
]
}
]
}