Session Takeover Vulnerability in WAVLINK Quantum D4G (WN531G3) Firmware M31G3.V5030.200325

Session Takeover Vulnerability in WAVLINK Quantum D4G (WN531G3) Firmware M31G3.V5030.200325

CVE-2022-40622 · HIGH Severity

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

The WAVLINK Quantum D4G (WN531G3) running firmware version M31G3.V5030.200325 uses IP addresses to hold sessions and does not not use session tokens. Therefore, if an attacker changes their IP address to match the logged-in administrator's, or is behind the same NAT as the logged in administrator, session takeover is possible.

Learn more about our Web Application Penetration Testing UK.