CVE-2022-2486

High PUBLISHED

WAVLINK WN535K2/WN535K3 os command injection

WAVLINK · WN535K2, WN535K3

Not yet in CISA KEV

Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
High
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
Not yet in CISA KEV
CVSS / EPSS
8.0 High

At a Glance

A vulnerability, which was classified as critical, was found in WAVLINK WN535K2 and WN535K3. This affects an unknown part of the file /cgi-bin/mesh.cgi?page=upgrade. The manipulation of the argument key leads to os command injection. The exploit has been disclosed to the public and may be used.

nuclei_scanner
CVE Published
Jul 20, 2022
Exploitation Reported
Sep 18, 2025
CVSS
8.0 High
EPSS
Low complexity No user interaction

Affected Versions

Vendor Product Version Status
WAVLINK
WN535K2

n/a

Affected
WAVLINK
WN535K3

n/a

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.