Command Injection Vulnerability in Wavlink WL-WN531P3 Router
CVE-2022-23900

9.8CRITICAL

Key Information:

Vendor

Wavlink

Vendor
CVE Published:
7 April 2022

What is CVE-2022-23900?

A command injection vulnerability exists in the API of the Wavlink WL-WN531P3 router. This allows attackers to execute arbitrary commands on the affected device by sending specially crafted POST requests to the /cgi-bin/adm.cgi endpoint. Exploiting this vulnerability can lead to unauthorized access and control over the router, posing significant security risks to the network it governs. It is crucial for users to update their devices and ensure proper security measures are in place.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.