7.5

CVE-2022-44356

Exploit
WAVLINK Quantum D4G (WL-WN531G3) running firmware versions M31G3.V5030.201204 and M31G3.V5030.200325 has an access control issue which allows unauthenticated attackers to download configuration data and log files.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wavlink ≫ Wl-wn531g3 Firmware Version m31g3.v5030.200325
   Wavlink ≫ Wl-wn531g3 Version -
Wavlink ≫ Wl-wn531g3 Firmware Version m31g3.v5030.201204
   Wavlink ≫ Wl-wn531g3 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.73% 0.846
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA-ADP 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-552 Files or Directories Accessible to External Parties

The product makes files or directories accessible to unauthorized actors, even though they should not be.

https://github.com/strik3r0x1/Vulns/blob/main/Wavlink%20WL-WN531G3.md
Third Party Advisory
Exploit