漏洞描述 一些Wavlink产品受到一个漏洞的影响,该漏洞可能允许未经身份验证的远程用户以root用户身份在Wavlink设备上执行任意命令。touchlist_sync.cgi文件的IP参数存在命令执行漏洞,攻击者可通过该漏洞获取服务器权限。
相关漏洞推荐 CVE-2022-2486: Wavlink WN535K2/WN535K3 - OS Command Injection POC 2025-09-01 | Wavlink WN535K2 WN535K3 Wavlink WN535K2 and WN535K3 routers are susceptible to OS command injection in an unknown part of th... CVE-2022-2487: Wavlink WN535K2/WN535K3 - OS Command Injection POC 2025-09-01 | Wavlink WN535K2/WN535K3 Wavlink WN535K2 and WN535K3 routers are susceptible to OS command injection which affects unknown co... CVE-2022-2488: Wavlink WN535K2/WN535K3 - OS Command Injection POC 2025-09-01 | Wavlink WN535K2 Wavlink WN535K2 and WN535K3 routers are susceptible to OS command injection in /cgi-bin/touchlist_sy... SourceCodester Pet Grooming Management Software SQL注入漏洞 无POC 2025-09-22 00:22:31 | SourceCodester Pet Grooming Management Software SourceCodester Pet Grooming Management Software是SourceCodester开源的一个宠物美容管理系统。 SourceCodester Pet Groo... D-Link DIR-645 命令注入漏洞 无POC 2025-09-22 00:22:31 | D-Link DIR-645 D-Link DIR-645是中国友讯(D-Link)公司的一款无线路由器。 D-Link DIR-645 105B01版本存在命令注入漏洞,该漏洞源于对文件/soap.cgi中参数service的错...