PT-2022-25423 · Wavlink · Wavlink Quantum D4G

Corey Hartman

·

Published

2022-09-13

·

Updated

2022-09-19

·

CVE-2022-40623

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WAVLINK Quantum D4G (WN531G3) version M31G3.V5030.200325
Description The issue is related to the lack of anti-CSRF tokens, which can be exploited to achieve remote, unauthenticated command execution when combined with other issues.
Recommendations For WAVLINK Quantum D4G (WN531G3) version M31G3.V5030.200325, consider implementing anti-CSRF tokens to prevent remote command execution. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

CSRF

Weakness Enumeration

Related Identifiers

CVE-2022-40623

Affected Products

Wavlink Quantum D4G