{
  "data_type": "CVE",
  "data_format": "MITRE",
  "data_version": "4.0",
  "generator": {
    "engine": "Vulnogram 0.0.9"
  },
  "CVE_data_meta": {
    "ID": "CVE-2022-40623",
    "ASSIGNER": "cve@rapid7.com",
    "DATE_PUBLIC": "2022-08-02T14:00:00.000Z",
    "TITLE": "WAVLINK Quantum D4G (WN531G3) CSRF",
    "AKA": "",
    "STATE": "PUBLIC"
  },
  "source": {
    "defect": [],
    "advisory": "",
    "discovery": "EXTERNAL"
  },
  "affects": {
    "vendor": {
      "vendor_data": [
        {
          "vendor_name": "WAVLINK",
          "product": {
            "product_data": [
              {
                "product_name": "WN531G3",
                "version": {
                  "version_data": [
                    {
                      "version_name": "M31G3.V5030.200325",
                      "version_affected": "<=",
                      "version_value": "M31G3.V5030.200325",
                      "platform": ""
                    }
                  ]
                }
              }
            ]
          }
        }
      ]
    }
  },
  "problemtype": {
    "problemtype_data": [
      {
        "description": [
          {
            "lang": "eng",
            "value": "CWE-352 Cross-Site Request Forgery (CSRF)"
          }
        ]
      }
    ]
  },
  "description": {
    "description_data": [
      {
        "lang": "eng",
        "value": "The WAVLINK Quantum D4G (WN531G3) running firmware version M31G3.V5030.200325 does not utilize anti-CSRF tokens, which, when combined with other issues (such as CVE-2022-35518), can lead to remote, unauthenticated command execution."
      }
    ]
  },
  "references": {
    "reference_data": [
      {
        "refsource": "MISC",
        "url": "https://youtu.be/cSileV8YbsQ?t=1028",
        "name": "https://youtu.be/cSileV8YbsQ?t=1028"
      }
    ]
  },
  "credit": [
    {
      "lang": "eng",
      "value": "Corey Hartman"
    }
  ]
}
