{"cve":"CVE-2022-2488","epss":{"score":0.33764},"mitre":{"cpes":[],"created":"2022-07-20T11:35:34+00:00","description":"A vulnerability was found in WAVLINK WN535K2 and WN535K3 and classified as critical. This issue affects some unknown processing of the file /cgi-bin/touchlist_sync.cgi. The manipulation of the argument IP leads to os command injection. The exploit has been disclosed to the public and may be used.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":8,"vector":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"cvssV4_0":{}},"mitre_repo_path":"cves/2022/2xxx/CVE-2022-2488.json","references":["https://github.com/1angx/webray.com.cn/blob/main/Wavlink/Wavlink%20touchlist_sync.cgi.md","https://vuldb.com/?id.204539"],"title":"WAVLINK WN535K2/WN535K3 touchlist_sync.cgi os command injection","updated":"2025-04-15T14:04:06.986000+00:00","vendors":[],"weaknesses":["CWE-78"]},"nvd":{"cpes":["cpe:2.3:h:wavlink:wl-wn535k2:-:*:*:*:*:*:*:*","cpe:2.3:h:wavlink:wl-wn535k3:-:*:*:*:*:*:*:*","cpe:2.3:o:wavlink:wl-wn535k2_firmware:-:*:*:*:*:*:*:*","cpe:2.3:o:wavlink:wl-wn535k3_firmware:-:*:*:*:*:*:*:*"],"created":"2022-07-20T12:15:08.477000+00:00","description":"A vulnerability was found in WAVLINK WN535K2 and WN535K3 and classified as critical. This issue affects some unknown processing of the file /cgi-bin/touchlist_sync.cgi. The manipulation of the argument IP leads to os command injection. The exploit has been disclosed to the public and may be used.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":8.0,"vector":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"cvssV4_0":{}},"nvd_repo_path":"2022/CVE-2022-2488.json","references":["https://github.com/1angx/webray.com.cn/blob/main/Wavlink/Wavlink%20touchlist_sync.cgi.md","https://vuldb.com/?id.204539","https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-1999"],"title":null,"updated":"2026-06-17T04:41:59.390000+00:00","vendors":["wavlink","wavlink$PRODUCT$wl-wn535k2","wavlink$PRODUCT$wl-wn535k2_firmware","wavlink$PRODUCT$wl-wn535k3","wavlink$PRODUCT$wl-wn535k3_firmware"],"weaknesses":["CWE-78"]},"opencve":{"changes":[{"created":"2025-01-14T16:45:00+00:00","data":[{"details":{"added":["https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-1999"],"removed":[]},"type":"references"}],"id":"a7a9e81e-9be6-4fa3-bba0-e89c302b28f7"},{"created":"2025-04-15T15:15:00+00:00","data":[{"details":{"added":{"ssvc":{"options":{"Automatable":"no","Exploitation":"poc","Technical Impact":"total"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"c663ccc6-9204-43e8-9ce1-05d6168e8a03"}],"cpes":{"data":["cpe:2.3:h:wavlink:wl-wn535k2:-:*:*:*:*:*:*:*","cpe:2.3:h:wavlink:wl-wn535k3:-:*:*:*:*:*:*:*","cpe:2.3:o:wavlink:wl-wn535k2_firmware:-:*:*:*:*:*:*:*","cpe:2.3:o:wavlink:wl-wn535k3_firmware:-:*:*:*:*:*:*:*"],"providers":["nvd"]},"created":{"data":"2022-07-20T11:35:34+00:00","provider":"mitre"},"description":{"data":"A vulnerability was found in WAVLINK WN535K2 and WN535K3 and classified as critical. This issue affects some unknown processing of the file /cgi-bin/touchlist_sync.cgi. The manipulation of the argument IP leads to os command injection. The exploit has been disclosed to the public and may be used.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{},"provider":null},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{"score":8,"vector":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"provider":"mitre"},"cvssV4_0":{"data":{},"provider":null},"epss":{"data":{"score":0.33764},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"no","Exploitation":"poc","Technical Impact":"total"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://github.com/1angx/webray.com.cn/blob/main/Wavlink/Wavlink%20touchlist_sync.cgi.md","https://vuldb.com/?id.204539","https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-1999"],"providers":["mitre","nvd"]},"title":{"data":"WAVLINK WN535K2/WN535K3 touchlist_sync.cgi os command injection","provider":"mitre"},"updated":{"data":"2025-04-15T14:04:06.986000+00:00","provider":"mitre"},"vendors":{"data":["wavlink","wavlink$PRODUCT$wl-wn535k2","wavlink$PRODUCT$wl-wn535k2_firmware","wavlink$PRODUCT$wl-wn535k3","wavlink$PRODUCT$wl-wn535k3_firmware"],"providers":["nvd"]},"weaknesses":{"data":["CWE-78"],"providers":["mitre","nvd"]}},"vulnrichment":{"cpes":[],"created":"2022-07-20T11:35:34+00:00","description":"A vulnerability was found in WAVLINK WN535K2 and WN535K3 and classified as critical. This issue affects some unknown processing of the file /cgi-bin/touchlist_sync.cgi. The manipulation of the argument IP leads to os command injection. The exploit has been disclosed to the public and may be used.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"no","Exploitation":"poc","Technical Impact":"total"},"version":"2.0.3"}},"references":[],"title":"WAVLINK WN535K2/WN535K3 touchlist_sync.cgi os command injection","updated":"2025-04-14T16:55:11.952000+00:00","vendors":[],"vulnrichment_repo_path":"2022/2xxx/CVE-2022-2488.json","weaknesses":[]}}