Exposure of resource to wrong sphere issue exists in WL-WN531AX2 firmware versions prior to 2023526, which may allow a network-adjacent attacker to use functions originally available after login without logging in.
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
Link | Tags |
---|---|
https://www.wavlink.com/en_us/firmware/details/932108ffc5.html | product patch |
https://jvn.jp/en/jp/JVN78634340/ | third party advisory patch |