peter bassill · operator
$ cve CVE-2022-34047 JSON

CVE-2022-34047 EXPLOIT

7.5
HIGH · CVSS 3.1 · EPSS 21.8% (pctl 98)

Patch early

A public exploit exists.

Description

An access control issue in Wavlink WN530HG4 M30HG4.V5030.191116 allows attackers to obtain usernames and passwords via view-source:http://IP_ADDRESS/set_safety.shtml?r=52300 and searching for [var syspasswd].

Scoring

CVSS7.5 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS21.82% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-668
On CISA KEVno
Public exploityes
Published2022-07-20
Last modified2026-06-17

Affected (2)

VendorProduct
wavlinkwl-wn530hg4
wavlinkwl-wn530hg4 firmware

Public exploits

SourceTitleDate
exploit-dbWavlink WN530HG4 - Password Disclosure2022-08-01

References

→ the Explorer  ·  watch your stack  ·  NVD