CVE-2022-40622
Estado: ModificadaAlta (8.8)—
The WAVLINK Quantum D4G (WN531G3) running firmware version M31G3.V5030.200325 uses IP addresses to hold sessions and does not not use session tokens. Therefore, if an attacker changes their IP address to match the logged-in administrator's, or is behind the same NAT as the logged in administrator, session takeover is possible.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 8.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.74%
- Percentil entre todas las CVEs puntuadas: 53
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-304
- CWE-287
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-40622",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "cve@rapid7.com",
"affectedData": [
{
"vendor": "WAVLINK",
"product": "WN531G3",
"versions": [
{
"status": "affected",
"version": "M31G3.V5030.200325",
"versionType": "custom",
"lessThanOrEqual": "M31G3.V5030.200325"
}
]
}
]
}
],
"published": "2022-09-13T21:15:10.197",
"references": [
{
"url": "https://youtu.be/cSileV8YbsQ?t=655",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "cve@rapid7.com"
},
{
"url": "https://youtu.be/cSileV8YbsQ?t=655",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "cve@rapid7.com",
"description": [
{
"lang": "en",
"value": "CWE-304"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-287"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The WAVLINK Quantum D4G (WN531G3) running firmware version M31G3.V5030.200325 uses IP addresses to hold sessions and does not not use session tokens. Therefore, if an attacker changes their IP address to match the logged-in administrator's, or is behind the same NAT as the logged in administrator, session takeover is possible."
},
{
"lang": "es",
"value": "El WAVLINK Quantum D4G (WN531G3) ejecutando la versión de firmware M31G3.V5030.200325, usa direcciones IP para mantener las sesiones y no usa tokens de sesión. Por lo tanto, si un atacante cambia su dirección IP para que coincida con la del administrador que ha iniciado la sesión, o está detrás del mismo NAT que el administrador que ha iniciado la sesión, es posible una toma de control de sesión"
}
],
"lastModified": "2026-06-17T05:01:43.647",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:wavlink:wn531g3_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B8E4F42B-0D2E-4D51-A8C7-37C5D95ECB2C",
"versionEndIncluding": "m31g3.v5030.200325"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:wavlink:wn531g3:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "3AE2AAA4-71D2-4B70-81FB-836F1A419DBC"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cve@rapid7.com"
}