7.2
CVE-2023-32612
- EPSS 0.07%
- Veröffentlicht 30.06.2023 05:15:09
- Zuletzt bearbeitet 27.11.2024 16:15:09
- Quelle vultures@jpcert.or.jp
- CVE-Watchlists
- Unerledigt
Client-side enforcement of server-side security issue exists in WL-WN531AX2 firmware versions prior to 2023526, which may allow an attacker with an administrative privilege to execute OS commands with the root privilege.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wavlink ≫ Wl-wn531ax2 Firmware Version < 2023526
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.07% | 0.204 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.2 | 1.2 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
CWE-565 Reliance on Cookies without Validation and Integrity Checking
The product relies on the existence or values of cookies when performing security-critical operations, but it does not properly ensure that the setting is valid for the associated user.