← Vulnerability feed

Vulnerability record · CVE-2022-31847 · published 14 June 2022

CVE-2022-31847: Wavlink wn579x3 firmware vulnerability

Wavlink · Wn579x3 Firmware

A vulnerability in /cgi-bin/ExportAllSettings.sh of WAVLINK WN579 X3 M79X3.V5030.180719 allows attackers to obtain sensitive router information via a crafted POST request.

7.5 CVSS 3.1 High EPSS 6.6% · top 6.4% CWE-425 · CWE-425
7.5CVSS 3.1 base score, v2 5.0
6.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A vulnerability in /cgi-bin/ExportAllSettings.sh of WAVLINK WN579 X3 M79X3.V5030.180719 allows attackers to obtain sensitive router information via a crafted POST request.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-31847 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-3380Wavlink wn579x3 firmware injection vulnerabilityA vulnerability classified as critical has been found in Wavlink WN579X3 up to 20230615. Affected is an unknown function of the file /cgi-bin/adm.cgi…EPSS 3.9%9.8CVE-2020-13117Wavlink router login key parameter command injectionWavlink WN575A4, WN579X3 and WN530G3A devices through 2020-05-15 pass the login request 'key' parameter to a command without sanitization, allowing c…EPSS 69%analysed7.5CVE-2020-10974Wavlink wl-wn575a3 firmware missing authentication for critical function vulnerabilityAn issue was discovered affecting a backup feature where a crafted POST request returns the current configuration of the device in cleartext, includi…EPSS 1.7%7.5CVE-2020-12266Wavlink wl-wn579g3 firmware missing authentication for critical function vulnerabilityAn issue was discovered where there are multiple externally accessible pages that do not require any sort of authentication, and store system informa…EPSS 1.8%7.5CVE-2024-45195Apache OFBiz forced browsing exposes restricted endpointsApache OFBiz before 18.12.16 is affected by a direct request (forced browsing) flaw, CWE-425, that lets a remote unauthenticated client reach functio…KEVEPSS 100%analysed5.3CVE-2021-26085Atlassian Confluence Server pre-auth arbitrary file read via /s/ endpointConfluence Server and Data Center expose a pre-authorization arbitrary file read through the /s/ endpoint, letting unauthenticated remote attackers v…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2022-31847), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.