Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5fcv-4vvr-f8ff

Опубликовано: 12 сент. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 5.5
CVSS3: 7.3

Описание

A vulnerability was found in Wavlink WL-WN578W2 221110. The impacted element is the function sub_409184 of the file /wizard_rep.shtml. The manipulation of the argument sel_EncrypTyp results in command injection. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

A vulnerability was found in Wavlink WL-WN578W2 221110. The impacted element is the function sub_409184 of the file /wizard_rep.shtml. The manipulation of the argument sel_EncrypTyp results in command injection. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

EPSS

Процентиль: 59%
0.00377
Низкий

5.5 Medium

CVSS4

7.3 High

CVSS3

Дефекты

CWE-74
CWE-77

Связанные уязвимости

CVSS3: 7.3
nvd
5 месяцев назад

A vulnerability was found in Wavlink WL-WN578W2 221110. The impacted element is the function sub_409184 of the file /wizard_rep.shtml. The manipulation of the argument sel_EncrypTyp results in command injection. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 5.3
fstec
5 месяцев назад

Уязвимость функции sub_409184() (/wizard_rep.shtml) микропрограммного обеспечения усилителей сигнала WAVLINK WL-WN578W2, позволяющая нарушителю выполнить произвольные команды

EPSS

Процентиль: 59%
0.00377
Низкий

5.5 Medium

CVSS4

7.3 High

CVSS3

Дефекты

CWE-74
CWE-77