PoC Index

CVE-2022-35518

CRITICAL 9.8EPSS 1.5%

WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 nas.cgi has no filtering on parameters: User1Passwd and User1, which leads to command injection in page /nas_disk.shtml.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v3.1
4.6 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
EPSS
1.52% chance of exploitation in the next 30 days, 73th percentile
Published
2022-08-09
Updated
2025-10-20

Proof-of-concept exploits (1)

References

Related