CVE-2022-40622
Severity CVSS v4.0:
Pending analysis
Type:
CWE-287
Authentication Issues
Publication date:
13/09/2022
Last modified:
19/09/2022
Description
The WAVLINK Quantum D4G (WN531G3) running firmware version M31G3.V5030.200325 uses IP addresses to hold sessions and does not not use session tokens. Therefore, if an attacker changes their IP address to match the logged-in administrator's, or is behind the same NAT as the logged in administrator, session takeover is possible.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:wavlink:wn531g3_firmware:*:*:*:*:*:*:*:* | m31g3.v5030.200325 (including) | |
| cpe:2.3:h:wavlink:wn531g3:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



