Vulnerability Details CVE-2022-35520
WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 api.cgi has no filtering on parameter ufconf, and this is a hidden parameter which doesn't appear in POST body, but exist in cgi binary. This leads to command injection in page /ledonoff.shtml.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 65.2%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2022-35520
-
cpe:2.3:h:wavlink:wn530h4:-
-
cpe:2.3:h:wavlink:wn531p3:-
-
cpe:2.3:h:wavlink:wn533a8:-
-
cpe:2.3:h:wavlink:wn535g3:-
-
cpe:2.3:h:wavlink:wn572hp3:-
-
cpe:2.3:o:wavlink:wn530h4_firmware:-
-
cpe:2.3:o:wavlink:wn531p3_firmware:-
-
cpe:2.3:o:wavlink:wn533a8_firmware:-
-
cpe:2.3:o:wavlink:wn535g3_firmware:-
-
cpe:2.3:o:wavlink:wn572hp3_firmware:-