RULE(RULE ID:337860)

Rule General Information
Release Date: 2024-03-19
Rule Name: WAVLINK touchlist_sync.cgi Command Injection Vulnerability (CVE-2022-2488)
Severity:
CVE ID:
Rule Protection Details
Description: A vulnerability was found in WAVLINK WN535K2 and WN535K3 and classified as critical. This issue affects some unknown processing of the file /cgi-bin/touchlist_sync.cgi. The manipulation of the argument IP leads to os command injection. The exploit has been disclosed to the public and may be used.
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Others
Reference: https://github.com/1angx/webray.com.cn/blob/main/Wavlink/Wavlink
https://vuldb.com/
https://cxsecurity.com/cveshow/CVE-2022-2488/
Solutions
Refer to the announcement or patch by the vendor: https://www.wavlink.com/zh_cn/firmware.html