Client-side enforcement of server-side security issue exists in WL-WN531AX2 firmware versions prior to 2023526, which may allow an attacker with an administrative privilege to execute OS commands with the root privilege.
The product relies on the existence or values of cookies when performing security-critical operations, but it does not properly ensure that the setting is valid for the associated user.
Link | Tags |
---|---|
https://www.wavlink.com/en_us/firmware/details/932108ffc5.html | product patch |
https://jvn.jp/en/jp/JVN78634340/ | third party advisory patch |