CVE-2022-40622 Information
Sep 14, 2022
cve
Description
The WAVLINK Quantum D4G (WN531G3) running firmware version M31G3.V5030.200325 uses IP addresses to hold sessions and does not not use session tokens. Therefore if an attacker changes their IP address to match the logged-in administrator’s or is behind the same NAT as the logged in administrator session takeover is possible.
Reference
https://youtu.be/cSileV8YbsQ?t=655
Share on: