S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-2488 Scanner

CVE-2022-2488 scanner - Command Injection vulnerability in WAVLINK WN535K2 and WN535K3

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.8k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-2488
9.8
CVSShigh
Exploitable from an adjacent network · low-privilege account sufficient.

A vulnerability was found in WAVLINK WN535K2 and WN535K3 and classified as critical. This issue affects some unknown processing of the file /cgi-bin/touchlist_sync.cgi. The manipulation of the argument IP leads to os command injection. The exploit has been disclosed to the public and may be used.

Attack Vector
Adjacent
Privileges Req.
Low
User Interaction
None
Affected
WN535K2by WAVLINK
n/a
WN535K3by WAVLINK
n/a
Updated Aug 22, 2026View on NVD →
Detail

WAVLINK WN535K2 and WN535K3 are wireless routers commonly utilized for home and small business network setups. These routers are popular due to their easy-to-use interface, dual-band support, and compatibility with various Internet Service Providers (ISPs). The WAVLINK WN535K2 and WN535K3 are designed to provide seamless internet connectivity and network management to their users.

Recently, a critical vulnerability named CVE-2022-2488 has been discovered in WAVLINK WN535K2 and WN535K3 routers. This vulnerability affects the file /cgi-bin/touchlist_sync.cgi and can lead to os command injection. This means that an attacker can remotely execute arbitrary commands within the router and take full control of the device. Cybercriminals can exploit such vulnerabilities to access sensitive information, infect connected devices with malware or launch DDoS attacks.

When exploited, CVE-2022-2488 can result in severe consequences for users of WAVLINK WN535K2 and WN535K3 routers. Attackers can gain unauthorized access to the network, and sensitive information such as login credentials, financial data, and personal information can be accessed. The exploit can also lead to a complete network outage, causing significant downtime and loss of revenue for businesses. In summary, CVE-2022-2488 vulnerability can seriously compromise the security and functionality of WAVLINK WN535K2 and WN535K3 routers.

Finally, at s4e.io, users can easily and quickly learn about vulnerabilities in their digital assets. Thanks to the pro features of our platform, users can leverage the expertise of our security professionals to create a security program that meets their unique needs. By subscribing to our platform, users can receive real-time alerts about new vulnerabilities and emerging threats, ensuring that they are always up-to-date on the latest security risks. Don't put your digital assets at risk any longer - join s4e.io today!

 

REFERENCES

Solution Advice

To protect against CVE-2022-2488, users of WAVLINK WN535K2 and WN535K3 routers should take appropriate precautions, including:

  • First and foremost, upgrade the firmware of their routers to the latest version available.
  • Change the default username and password of the router via the settings of the device.
  • Disable remote access to the router and only allow access from trusted IP addresses.
  • Keep an eye on log files and router activity to detect any signs of suspicious behavior.
  • Employ anti-malware and antivirus software to detect and block any attacks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.