Hardcoded Encryption Key Vulnerability in Wavlink Products
CVE-2022-34045
9.8CRITICAL
What is CVE-2022-34045?
The Wavlink WN530HG4 device contains a hardcoded encryption and decryption key for its configuration files, which can be found at /etc_ro/lighttpd/www/cgi-bin/ExportAllSettings.sh. This flaw exposes sensitive settings, potentially allowing unauthorized access to critical configuration data and settings within the device.
