🤬
..
README.md Loading last commit info...
poc.html
README.md

CVE-2022-23900

My first official CVE. Full write-up here.

Description:

A command injection vulnerability in the API of the Wavlink WL-WN531P3 router, version M31G3.V5030.201204, allows an attacker to achieve unauthorized remote code execution via a malicious POST request through /cgi-bin/adm.cgi.

Exploit

I have included poc.html. This is a simple PoC to leak /etc/passwd in the response body, but it could be used to execute any arbitrary command.

Please wait...
Page is in error, reload to recover