« Volver al listado

CVE-2022-40622

Estado: ModificadaAlta (8.8)—

The WAVLINK Quantum D4G (WN531G3) running firmware version M31G3.V5030.200325 uses IP addresses to hold sessions and does not not use session tokens. Therefore, if an attacker changes their IP address to match the logged-in administrator's, or is behind the same NAT as the logged in administrator, session takeover is possible.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-40622",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "cve@rapid7.com",
      "affectedData": [
        {
          "vendor": "WAVLINK",
          "product": "WN531G3",
          "versions": [
            {
              "status": "affected",
              "version": "M31G3.V5030.200325",
              "versionType": "custom",
              "lessThanOrEqual": "M31G3.V5030.200325"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-09-13T21:15:10.197",
  "references": [
    {
      "url": "https://youtu.be/cSileV8YbsQ?t=655",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "cve@rapid7.com"
    },
    {
      "url": "https://youtu.be/cSileV8YbsQ?t=655",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cve@rapid7.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-304"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The WAVLINK Quantum D4G (WN531G3) running firmware version M31G3.V5030.200325 uses IP addresses to hold sessions and does not not use session tokens. Therefore, if an attacker changes their IP address to match the logged-in administrator's, or is behind the same NAT as the logged in administrator, session takeover is possible."
    },
    {
      "lang": "es",
      "value": "El WAVLINK Quantum D4G (WN531G3) ejecutando la versión de firmware M31G3.V5030.200325, usa direcciones IP para mantener las sesiones y no usa tokens de sesión. Por lo tanto, si un atacante cambia su dirección IP para que coincida con la del administrador que ha iniciado la sesión, o está detrás del mismo NAT que el administrador que ha iniciado la sesión, es posible una toma de control de sesión"
    }
  ],
  "lastModified": "2026-06-17T05:01:43.647",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:wavlink:wn531g3_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B8E4F42B-0D2E-4D51-A8C7-37C5D95ECB2C",
              "versionEndIncluding": "m31g3.v5030.200325"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:wavlink:wn531g3:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "3AE2AAA4-71D2-4B70-81FB-836F1A419DBC"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve@rapid7.com"
}