WAVLINK Quantum D4G (WN531G3) Pass-The-Hash
CVE-2022-40621

7.5HIGH

Key Information:

Vendor

Wavlink

Status
Vendor
CVE Published:
13 September 2022

What is CVE-2022-40621?

Because the WAVLINK Quantum D4G (WN531G3) running firmware version M31G3.V5030.200325 and earlier communicates over HTTP and not HTTPS, and because the hashing mechanism does not rely on a server-supplied key, it is possible for an attacker with sufficient network access to capture the hashed password of a logged on user and use it in a classic Pass-the-Hash style attack.

Affected Version(s)

WN531G3 M31G3.V5030.200325

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Corey Hartman
.