CVE-2022-48165 is an access control vulnerability in the /cgi-bin/ExportLogs.sh component of Wavlink WL-WN530H4 M30H4.V5030.210121 firmware. This flaw allows unauthenticated attackers to download sensitive configuration data and log files, potentially exposing administrative credentials. Rated with a CVSS score of 7.5 (High), it presents a low-complexity network attack vector with a high impact on confidentiality. While there is no evidence of active exploitation or publicly available Metasploit modules, Nuclei templates exist, and the vulnerability has not garnered significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
m30h4.v5030.210121CPE matchmatch criteria | cpe:2.3:o:wavlink:wl-wn530h4_firmware:m30h4.v5030.210121:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.