VYPR
Unrated severityNVD Advisory· Published Aug 9, 2022· Updated Oct 20, 2025

CVE-2022-35518

CVE-2022-35518

Description

WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 nas.cgi has no filtering on parameters: User1Passwd and User1, which leads to command injection in page /nas_disk.shtml.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

WAVLINK WN572HP3 and four other models are vulnerable to command injection via the nas.cgi endpoint when parameters User1Passwd and User1 are not sanitized.

Vulnerability

Multiple WAVLINK router models — WN572HP3, WN533A8, WN530H4, WN535G3, and WN531P3 — are affected by a command injection vulnerability in the nas.cgi script. The parameters User1Passwd and User1 are passed without any input filtering, leading to injection into the /nas_disk.shtml page [1].

Exploitation

An attacker must first authenticate to the router's management interface. Once logged in, the attacker can craft a POST request to /cgi-bin/nas.cgi and inject arbitrary system commands into either the User1Passwd or User1 parameters by appending a command after a semicolon (e.g., xxx;command) [1].

Impact

Successful exploitation allows an authenticated attacker to execute arbitrary operating system commands on the router with root privileges, leading to full device compromise. This can result in complete loss of confidentiality, integrity, and availability [1].

Mitigation

As of the publication date (2022-08-09), no fixed firmware version or patch has been announced for any of the affected models. Users should restrict access to the management interface to trusted networks only and monitor for official updates from WAVLINK. There is no indication that this CVE is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

6

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.