S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 8, 2024

CVE-2022-34576 Scanner

CVE-2022-34576 scanner - Code Injection vulnerability in WAVLINK WN535 G3

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.1k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-34576
7.5
CVSS

A vulnerability in /cgi-bin/ExportAllSettings.sh of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to execute arbitrary code via a crafted POST request.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

WAVLINK WN535 G3 is a wireless router designed for homes and small offices to provide a stable and fast internet connection. Its advanced features such as QoS, guest network, and parental control make it a popular choice among users. The router also comes with multiple ports for wired connections, including one WAN port and four LAN ports. Its compact size and sleek design make it easy to install and blend with the interiors.

However, despite the various features that make it a popular choice, the WAVLINK WN535 G3 is vulnerable to a serious security flaw - CVE-2022-34576. This vulnerability relates to the /cgi-bin/ExportAllSettings.sh script that can be exploited by attackers to execute arbitrary code by sending a crafted POST request. As a result, an attacker can gain unauthorized access to sensitive information, install malicious software, or even take control of the device.

Exploitation of this vulnerability can lead to serious consequences, including data theft, privacy breaches, and network disruption. Attackers can easily gain access to usernames, passwords, and other confidential information, leading to identity theft or financial loss. Additionally, the attacker can install malware or ransomware on the router, causing network-wide disruption and even rendering the router unusable.

At s4e.io, we offer a comprehensive platform that provides detailed and up-to-date information on vulnerabilities affecting digital assets, including routers. With the platform's pro features, users can easily and quickly learn about potential security threats affecting their devices and networks. By subscribing to our service, you can enjoy advanced features such as vulnerability scans, real-time alerts, and detailed reports to stay on top of the latest security threats. Stay secure with s4e.io.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users are advised to take the following precautions:

  • Update the router to the latest firmware version, which often includes security patches.
  • Change the default login credentials to strong ones.
  • Disable remote management if not required.
  • Monitor network traffic for suspicious activity.
  • Use a reputable security solution that provides ongoing protection.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.