.. | |||
README.md | Loading last commit info... | ||
poc.html |
README.md
CVE-2022-23900
My first official CVE. Full write-up here.
Description:
A command injection vulnerability in the API of the Wavlink WL-WN531P3 router, version M31G3.V5030.201204, allows an attacker to achieve unauthorized remote code execution via a malicious POST request through /cgi-bin/adm.cgi.
Exploit
I have included poc.html
. This is a simple PoC to leak /etc/passwd
in the response body, but it could be used to execute any arbitrary command.