PT-2022-16952 · Wavlink · Wavlink Wn535K2+1

·

CVE-2022-2488

·

Published

2022-07-20

·

Updated

2025-01-14

CVSS v3.1

8.0

High

VectorAV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WAVLINK WN535K2 WAVLINK WN535K3
Description A critical issue affects the unknown processing of the file /cgi-bin/touchlist sync.cgi. The manipulation of the argument IP leads to os command injection. The exploit has been disclosed to the public and may be used.
Recommendations For WAVLINK WN535K2, as a temporary workaround, consider restricting access to the /cgi-bin/touchlist sync.cgi file until a patch is available. For WAVLINK WN535K3, as a temporary workaround, consider restricting access to the /cgi-bin/touchlist sync.cgi file until a patch is available. Avoid using the argument IP in the affected API endpoint until the issue is resolved.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-2488

Affected Products

Wavlink Wn535K2
Wavlink Wn535G3