This is a summary of the AI-generated 10-question deep analysis. The full version (longer answers, follow-up Q&A, related CVEs) requires login.
Read the full analysis โ
Q1What is this vulnerability? (Essence + Consequences)
๐จ **Essence**: OS Command Injection in WAVLINK routers. ๐ **Consequences**: Attackers can execute arbitrary commands, steal data, modify system files, or take full control of the device.โฆ
๐ก๏ธ **Root Cause**: CWE-78 (OS Command Injection). ๐ฅ **Flaw**: The `/cgi-bin/nightled.cgi` script fails to sanitize the `start_hour` parameter. Malicious input is passed directly to the OS shell.
Q3Who is affected? (Versions/Components)
๐ฆ **Affected**: WAVLINK WN535K2 and WN535K3 Wireless Routers. ๐ญ **Vendor**: WAVLINK (China). โ ๏ธ **Scope**: Specifically targets the `nightled.cgi` component in these models.
Q4What can hackers do? (Privileges/Data)
๐ **Capabilities**: Full system control. ๐ **Data**: Access to sensitive info. ๐ **Privileges**: Execute malware, modify data, gain root/admin access without credentials. Itโs a total compromise.
Q5Is exploitation threshold high? (Auth/Config)
๐ **Auth Required**: Yes. PR:L (Privileges Required: Low). ๐ **Access**: Network Adjacent (AV:A). โ ๏ธ **Threshold**: Moderate. You need local network access and basic credentials, but no user interaction (UI:N) is needed.
Q6Is there a public Exp? (PoC/Wild Exploitation)
๐ **Public Exp**: Yes. ๐ **PoC**: Available via Nuclei templates (projectdiscovery). ๐ **Status**: Known vulnerability with documented exploitation paths. Not zero-day anymore.
Q7How to self-check? (Features/Scanning)
๐ **Self-Check**: Scan for `/cgi-bin/nightled.cgi`. ๐ก **Tool**: Use Nuclei or similar scanners with CVE-2022-2487 templates. ๐งช **Test**: Manipulate `start_hour` parameter to see if shell commands execute.
Q8Is it fixed officially? (Patch/Mitigation)
๐ ๏ธ **Patch**: Check WAVLINK official support for firmware updates. ๐ **Published**: July 20, 2022. โณ **Status**: Vendor should have released a fix by now. Verify your routerโs firmware version.
Q9What if no patch? (Workaround)
๐ง **Workaround**: Disable remote management if possible. ๐ซ **Network**: Isolate IoT devices on a separate VLAN. ๐ **Access Control**: Restrict access to the routerโs admin interface to trusted IPs only.
Q10Is it urgent? (Priority Suggestion)
๐ฅ **Priority**: HIGH. ๐ **CVSS**: 9.8 (Critical). ๐จ **Action**: Patch immediately or isolate. The impact is High (C:H, I:H, A:H). Donโt ignore this!