Vulnerability Details CVE-2022-35519
WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 firewall.cgi has no filtering on parameter add_mac, which leads to command injection in page /cli_black_list.shtml.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 66.2%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2022-35519
-
cpe:2.3:h:wavlink:wn530h4:-
-
cpe:2.3:h:wavlink:wn531p3:-
-
cpe:2.3:h:wavlink:wn533a8:-
-
cpe:2.3:h:wavlink:wn535g3:-
-
cpe:2.3:h:wavlink:wn572hp3:-
-
cpe:2.3:o:wavlink:wn530h4_firmware:-
-
cpe:2.3:o:wavlink:wn531p3_firmware:-
-
cpe:2.3:o:wavlink:wn533a8_firmware:-
-
cpe:2.3:o:wavlink:wn535g3_firmware:-
-
cpe:2.3:o:wavlink:wn572hp3_firmware:-