CVE-2022-34049
MEDIUMCVSS 5.3/10EPSS 2.18%
Last modified
CVE-2022-34049 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. An access control issue in Wavlink WN530HG4 M30HG4.V5030.191116 allows unauthenticated attackers to download log files and configuration data.. EPSS estimates a 2.18% chance of exploitation in the next 30 days.
Description
An access control issue in Wavlink WN530HG4 M30HG4.V5030.191116 allows unauthenticated attackers to download log files and configuration data.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Wavlink | Wl-Wn530hg4 Firmware | m30hg4.v5030.191116 |
References
- https://drive.google.com/file/d/1-eNgq6IS609bq2vB93c_N8jnZrJ2dgNF/view?usp=sharingExploit, Third Party Advisory
- https://drive.google.com/file/d/1ZeSwqu04OghLQXeG7emU-w-Amgadafqx/view?usp=sharingExploit, Third Party Advisory
- https://drive.google.com/file/d/1-eNgq6IS609bq2vB93c_N8jnZrJ2dgNF/view?usp=sharingExploit, Third Party Advisory
- https://drive.google.com/file/d/1ZeSwqu04OghLQXeG7emU-w-Amgadafqx/view?usp=sharingExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-34049?
An access control issue in Wavlink WN530HG4 M30HG4.V5030.191116 allows unauthenticated attackers to download log files and configuration data.
How severe is CVE-2022-34049?
CVE-2022-34049 has a CVSS score of 5.3/10 (MEDIUM severity). The EPSS model estimates a 2.18% probability of exploitation in the next 30 days.
How do I fix CVE-2022-34049?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-34042Barangay Management System v1.0 was discovered to contain a …7.2
- CVE-2022-34043Incorrect permissions for the folder C:\ProgramData\NoMachin…7.3
- CVE-2022-34045Wavlink WN530HG4 M30HG4.V5030.191116 was discovered to conta…9.8
- CVE-2022-34046An access control issue in Wavlink WN533A8 M33A8.V5030.19071…7.5
- CVE-2022-34047An access control issue in Wavlink WN530HG4 M30HG4.V5030.191…7.5
- CVE-2022-34048Wavlink WN533A8 M33A8.V5030.190716 was discovered to contain…6.1
- CVE-2022-3405Code execution and sensitive information disclosure due to e…8.8
- CVE-2022-34053The DR-Web-Engine package in PyPI v0.2.0b0 was discovered to…9.8
- CVE-2022-34054The Perdido package in PyPI v0.0.1 to v0.0.2 was discovered …9.8
- CVE-2022-34055The drxhello package in PyPI v0.0.1 was discovered to contai…9.8
- CVE-2022-34056The Watertools package in PyPI v0.0.0 was discovered to cont…9.8
- CVE-2022-34057The Scoptrial package in PyPI version v0.0.5 was discovered …9.8
Are you affected by CVE-2022-34049?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
