CVE-2022-2486 HIGH

CVE-2022-2486: WAVLINK WN535K2/WN535K3 os command injection

Vendor Wavlink
Product WN535K2
Weakness CWE-78
Published July 20, 2022
Last update April 15, 2025

CVSS base score

8.0/10
Attack vector Adjacent
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

A vulnerability, which was classified as critical, was found in WAVLINK WN535K2 and WN535K3. This affects an unknown part of the file /cgi-bin/mesh.cgi?page=upgrade. The manipulation of the argument key leads to os command injection. The exploit has been disclosed to the public and may be used.

Key dates

02Disclosure timeline

July 20, 2022 CVE published
April 15, 2025 Record updated