CVE-2022-2487 HIGH

CVE-2022-2487: WAVLINK WN535K2/WN535K3 nightled.cgi os command injection

Vendor Wavlink
Product WN535K2
Weakness CWE-78
Published July 20, 2022
Last update April 15, 2025

CVSS base score

8.0/10
Attack vector Adjacent
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

A vulnerability has been found in WAVLINK WN535K2 and WN535K3 and classified as critical. This vulnerability affects unknown code of the file /cgi-bin/nightled.cgi. The manipulation of the argument start_hour leads to os command injection. The exploit has been disclosed to the public and may be used.

Key dates

02Disclosure timeline

July 20, 2022 CVE published
April 15, 2025 Record updated