CVE-2022-41489

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
13/10/2022
Last modified:
15/05/2025

Description

WAYOS LQ_09 22.03.17V was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to send crafted requests to the server from the affected device. This vulnerability is exploitable due to a lack of authentication in the component Usb_upload.htm.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:wayos:lq-09_firmware:22.03.17:*:*:*:*:*:*:*
cpe:2.3:h:wayos:lq-09:-:*:*:*:*:*:*:*
cpe:2.3:o:wayos:lq-08_firmware:22.03.17:*:*:*:*:*:*:*
cpe:2.3:h:wayos:lq-08:-:*:*:*:*:*:*:*
cpe:2.3:o:wayos:lq-07_firmware:22.03.17:*:*:*:*:*:*:*
cpe:2.3:h:wayos:lq-07:-:*:*:*:*:*:*:*
cpe:2.3:o:wayos:lq-06_firmware:22.03.17:*:*:*:*:*:*:*
cpe:2.3:h:wayos:lq-06:-:*:*:*:*:*:*:*
cpe:2.3:o:wayos:lq-05_firmware:22.03.17:*:*:*:*:*:*:*
cpe:2.3:h:wayos:lq-05:-:*:*:*:*:*:*:*
cpe:2.3:o:wayos:lq-04_firmware:22.03.17:*:*:*:*:*:*:*
cpe:2.3:h:wayos:lq-04:-:*:*:*:*:*:*:*