RULE(RULE ID:337858)

Rule General Information
Release Date: 2024-03-19
Rule Name: WAVLINK mesh.cgi Command Injection Vulnerability (CVE-2022-2486)
Severity:
CVE ID:
Rule Protection Details
Description: A vulnerability, which was classified as critical, was found in WAVLINK WN535K2 and WN535K3. This affects an unknown part of the file /cgi-bin/mesh.cgi?page=upgrade. The manipulation of the argument key leads to os command injection. The exploit has been disclosed to the public and may be used.
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Others
Reference: https://github.com/1angx/webray.com.cn/blob/main/Wavlink/Wavlink
https://vuldb.com/
https://cxsecurity.com/cveshow/CVE-2022-2486/
Solutions
Refer to the announcement or patch by the vendor: https://www.wavlink.com/zh_cn/firmware.html