ZeroHour

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-2488
A vulnerability was found in WAVLINK WN535K2 and WN535K3 and classified as critical.

A vulnerability was found in WAVLINK WN535K2 and WN535K3 and classified as critical. This issue affects some unknown processing of the file /cgi-bin/touchlist_sync.cgi. The manipulation of the argument IP leads to os command injection. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
9.834% PoC
  • wavlink wl-wn535k2 firmware
  • wavlink wl-wn535k3 firmware
CVE-2024-34166
An os command injection vulnerability exists in the touchlist_sync.cgi touchlistsync() functionality of Wavlink AC3000 M33A8.V5030.210505.

An os command injection vulnerability exists in the touchlist_sync.cgi touchlistsync() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted set of HTTP requests can lead to arbitrary code execution. An attacker can send an HTTP request to trigger this vulnerability.

NVD description · AI analysis pending
9.8
group max
16% PoC ×2
  • wavlink wl-wn533a8 firmware
Full article388 words · extracted from blog.talosintelligence.com · click to collapse

Wednesday, January 15, 2025 08:00

Lilith >_> of Cisco Talos discovered these vulnerabilities. 

Forty-four vulnerabilities and sixty-three CVEs were discovered across ten .cgi and three .sh files, as well as the static login page, of the Wavlink AC3000 wireless router web application.  

The Wavlink AC3000 wireless router is one of the most popular gigabit routers in the US, in part due to both its potential speed capabilities and low price point. 

Talos is releasing these advisories in accordance with Cisco’s third-party vulnerability disclosure policy. Wavlink has declined to release a patch for these vulnerabilities.  

For Snort coverage that can detect the exploitation of these vulnerabilities, download the latest rule sets from Snort.org, and our latest Vulnerability Advisories are always posted on Talos Intelligence’s website.   

Static login vulnerability 

An attacker can send a specially crafted set of network packets over WAN to gain root access to the router via the wcrtrl service and static login credentials.  

Static Login 

Ten .cgi vulnerabilities 

An unauthenticated HTTP request can trigger the following types of vulnerabilities: 

touchlist_sync.cgi 

Login.cgi 

internet.cgi 

firewall.cgi 

adm.cgi 

wireless.cgi 

usbip.cgi 

qos.cgi 

openvpn.cgi 

nas.cgi 

Three .sh vulnerabilities 

Attackers can send specially crafted HTTP requests. A man-in-the-middle attack can trigger the fw_check.sh and update_filter_url.sh vulnerabilities. 

testsave.sh 

fw_check.sh 

update_filter_url.sh 

Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/slew-of-wavlink-vulnerabilities/