CVE-2022-35520 Information
Aug 11, 2022
cve
Description
WAVLINK WN572HP3 WN533A8 WN530H4 WN535G3 WN531P3 api.cgi has no filtering on parameter ufconf and this is a hidden parameter which doesn’t appear in POST body but exist in cgi binary. This leads to command injection in page /ledonoff.shtml.