Vulnerability Details CVE-2022-35524
WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 adm.cgi has no filtering on parameters: wlan_signal, web_pskValue, sel_EncrypTyp, sel_Automode, wlan_bssid, wlan_ssid and wlan_channel, which leads to command injection in page /wizard_rep.shtml.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 68.0%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2022-35524
-
cpe:2.3:h:wavlink:wn530h4:-
-
cpe:2.3:h:wavlink:wn531p3:-
-
cpe:2.3:h:wavlink:wn533a8:-
-
cpe:2.3:h:wavlink:wn535g3:-
-
cpe:2.3:h:wavlink:wn572hp3:-
-
cpe:2.3:o:wavlink:wn530h4_firmware:-
-
cpe:2.3:o:wavlink:wn531p3_firmware:-
-
cpe:2.3:o:wavlink:wn533a8_firmware:-
-
cpe:2.3:o:wavlink:wn535g3_firmware:-
-
cpe:2.3:o:wavlink:wn572hp3_firmware:-