S4E just found a high-severity finding from cve-2026-42945 scanner (version based)
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-35413 Scanner

CVE-2022-35413 scanner - Hard-Coded Credentials vulnerability in WAPPLES

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.7k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-35413
9.8
CVSS

WAPPLES through 6.0 has a hardcoded systemi account. A threat actor could use this account to access the system configuration and confidential information (such as SSL keys) via an HTTPS request to the /webapi/ URI on port 443 or 5001.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

WAPPLES is a highly advanced cloud-based Web Application Firewall (WAF) designed to provide web security for businesses of all sizes. It is developed by Penta Security and is specifically designed to detect and prevent web attacks. This powerful tool provides a secure gateway to your enterprise network by analyzing the incoming web traffic in real-time, thereby protecting your web applications and databases from various threats such as cross-site scripting, SQL injection, and DDoS attacks.

CVE-2022-35413 is a recently discovered vulnerability in the WAPPLES 6.0. This vulnerability arises from the presence of a hardcoded systemi account that allows unauthorized access to system configuration and confidential information such as SSL keys through an HTTPS request to the /webapi/ URI on port 443 or 5001. It can be exploited by a threat actor to gain access to critical network assets and cause harm to an organization.

When exploited, this vulnerability can lead to a wide range of consequences. First and foremost, unauthorized access can lead to a data breach and a possible compromise of confidential data. Such attacks can also cripple business operations by disrupting web applications. Moreover, attackers can gain persistence via backdoors and cause ongoing harm to the organization. The exploitation of this vulnerability can also damage the reputation and credibility of the organization, leading to customer distrust.

In conclusion, it is important to stay informed and proactive when it comes to securing digital assets from vulnerabilities. Thanks to the s4e.io platform, readers can learn about vulnerabilities in their digital assets with ease and take the necessary precautions to protect them. Businesses must prioritize security by implementing robust measures to keep up with the constantly evolving threat landscape and protect their critical assets from cybercriminals.

 

REFERENCES

Solution Advice

Various precautions can be taken to prevent the exploitation of this vulnerability. Some of them are as follows:

  • Update the WAPPLES device with the latest release that addresses the vulnerability.
  • Configure firewall rules to restrict traffic to vulnerable ports.
  • Deploy an Intrusion Detection System (IDS) to detect and alert on any unauthorized access or suspicious activity.
  • Use a Secure Sockets Layer (SSL) certificate to encrypt web traffic.
  • Limit the privileged access of the hardcoded systemi account.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.