« Volver al listado

CVE-2022-34767

Estado: ModificadaCrítica (9.8)—

Web page which "wizardpwd.asp" ALLNET Router model WR0500AC is prone to Authorization bypass vulnerability – the password, located at "admin" allows changing the http[s]://wizardpwd.asp/cgi-bin. Does not validate the user's identity and can be accessed publicly.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-34767",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cna@cyber.gov.il",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 5.9,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 3.7,
        "exploitabilityScore": 1.7
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cna@cyber.gov.il",
      "affectedData": [
        {
          "vendor": "ALLNET Gmbh",
          "product": "ALLNET Gmbh - ADSL/VDSL Router inkl. Modem and Wlan",
          "versions": [
            {
              "status": "affected",
              "version": "Update to the latest version",
              "lessThan": "Update to the latest version*",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-07-21T16:15:09.247",
  "references": [
    {
      "url": "https://www.gov.il/en/Departments/faq/cve_advisories",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cna@cyber.gov.il"
    },
    {
      "url": "https://www.gov.il/en/Departments/faq/cve_advisories",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-306"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Web page which \"wizardpwd.asp\" ALLNET Router model WR0500AC is prone to Authorization bypass vulnerability – the password, located at \"admin\" allows changing the http[s]://wizardpwd.asp/cgi-bin. Does not validate the user's identity and can be accessed publicly."
    },
    {
      "lang": "es",
      "value": "Página web que \"wizardpwd.asp\" ALLNET Router modelo WR0500AC es propenso a una vulnerabilidad de omisión de autorización - la contraseña, ubicada en \"admin\" permite cambiar el http[s]://wizardpwd.asp/cgi-bin. No comprueba la identidad del usuario y puede ser accedido públicamente"
    }
  ],
  "lastModified": "2026-06-17T04:50:53.373",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:allnet:all-wr0500ac_firmware:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BDBA5FC2-9765-4E63-AF75-B0D4B2F20333"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:allnet:all-wr0500ac:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "E2E209CD-5121-42F6-83B6-C9E2FDF1BE26"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cna@cyber.gov.il"
}