Vulnerability Details CVE-2022-35517
WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 adm.cgi has no filtering on parameters: web_pskValue, wl_Method, wlan_ssid, EncrypType, rwan_ip, rwan_mask, rwan_gateway, ppp_username, ppp_passwd and ppp_setver, which leads to command injection in page /wizard_router_mesh.shtml.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 66.3%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2022-35517
-
cpe:2.3:h:wavlink:wn530h4:-
-
cpe:2.3:h:wavlink:wn531p3:-
-
cpe:2.3:h:wavlink:wn533a8:-
-
cpe:2.3:h:wavlink:wn535g3:-
-
cpe:2.3:h:wavlink:wn572hp3:-
-
cpe:2.3:o:wavlink:wn530h4_firmware:-
-
cpe:2.3:o:wavlink:wn531p3_firmware:-
-
cpe:2.3:o:wavlink:wn533a8_firmware:-
-
cpe:2.3:o:wavlink:wn535g3_firmware:-
-
cpe:2.3:o:wavlink:wn572hp3_firmware:-