Description


The WAVLINK Quantum D4G (WN531G3) running firmware version M31G3.V5030.200325 does not utilize anti-CSRF tokens, which, when combined with other issues (such as CVE-2022-35518), can lead to remote, unauthenticated command execution.

References


https://youtu.be/cSileV8YbsQ?t=1028

ExploitThird Party Advisory

https://youtu.be/cSileV8YbsQ?t=1028

ExploitThird Party Advisory

Weaknesses



CWE-352


CWE-352

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

8.8 · High

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2022-09-13T19:15:10.253Z

3 years ago

Last modified

2024-11-21T06:21:43.923Z

1 year ago