An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to arbitrarily configure device settings via accessing the page mb_wifibasic.shtml.
References
Link | Resource |
---|---|
https://github.com/pghuanghui/CVE_Request/blob/main/WiFi-Repeater/WiFi-Repeater_mb_wifibasic.assets/WiFi-Repeater_mb_wifibasic.md | Exploit Third Party Advisory |
https://www.wavlink.com/en_us/category/REPEATER.html | Product Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2022-07-25 22:15
Updated : 2023-08-08 14:22
NVD link : CVE-2022-34573
Mitre link : CVE-2022-34573
CVE.ORG link : CVE-2022-34573
JSON object : View
Products Affected
wavlink
- wifi-repeater_firmware
CWE
CWE-425
Direct Request ('Forced Browsing')