Vulnerabilities > Wavlink

DATE CVE VULNERABILITY TITLE RISK
2023-06-23 CVE-2023-3380 Injection vulnerability in Wavlink Wn579X3 Firmware 20200515
A vulnerability classified as critical has been found in Wavlink WN579X3 up to 20230615.
network
low complexity
wavlink CWE-74
critical
9.8
2023-06-22 CVE-2023-29708 Unspecified vulnerability in Wavlink Wavrouter APP Rpt70Ha1.X
An issue was discovered in /cgi-bin/adm.cgi in WavLink WavRouter version RPT70HA1.x, allows attackers to force a factory reset via crafted payload.
network
low complexity
wavlink
7.5
2023-02-06 CVE-2022-48166 Missing Authorization vulnerability in Wavlink Wl-Wn530Hg4 Firmware M30Hg4.V5030.201217
An access control issue in Wavlink WL-WN530HG4 M30HG4.V5030.201217 allows unauthenticated attackers to download configuration data and log files and obtain admin credentials.
network
low complexity
wavlink CWE-862
7.5
2023-02-06 CVE-2022-48164 Unspecified vulnerability in Wavlink Wl-Wn533A8 Firmware M33A8.V5030.190716
An access control issue in the component /cgi-bin/ExportLogs.sh of Wavlink WL-WN533A8 M33A8.V5030.190716 allows unauthenticated attackers to download configuration data and log files and obtain admin credentials.
network
low complexity
wavlink
7.5
2023-02-03 CVE-2022-48165 Unspecified vulnerability in Wavlink Wl-Wn530H4 Firmware M30H4.V5030.210121
An access control issue in the component /cgi-bin/ExportLogs.sh of Wavlink WL-WN530H4 M30H4.V5030.210121 allows unauthenticated attackers to download configuration data and log files and obtain admin credentials.
network
low complexity
wavlink
7.5
2022-11-29 CVE-2022-44356 Files or Directories Accessible to External Parties vulnerability in Wavlink Wl-Wn531G3 Firmware M31G3.V5030.200325/M31G3.V5030.201204
WAVLINK Quantum D4G (WL-WN531G3) running firmware versions M31G3.V5030.201204 and M31G3.V5030.200325 has an access control issue which allows unauthenticated attackers to download configuration data and log files.
network
low complexity
wavlink CWE-552
7.5
2022-09-13 CVE-2022-40621 Authentication Bypass by Capture-replay vulnerability in Wavlink Wn531G3 Firmware M31G3.V5030.200325
Because the WAVLINK Quantum D4G (WN531G3) running firmware version M31G3.V5030.200325 and earlier communicates over HTTP and not HTTPS, and because the hashing mechanism does not rely on a server-supplied key, it is possible for an attacker with sufficient network access to capture the hashed password of a logged on user and use it in a classic Pass-the-Hash style attack.
network
high complexity
wavlink CWE-294
7.5
2022-09-13 CVE-2022-40622 Improper Authentication vulnerability in Wavlink Wn531G3 Firmware M31G3.V5030.200325
The WAVLINK Quantum D4G (WN531G3) running firmware version M31G3.V5030.200325 uses IP addresses to hold sessions and does not not use session tokens.
low complexity
wavlink CWE-287
8.8
2022-09-13 CVE-2022-40623 Cross-Site Request Forgery (CSRF) vulnerability in Wavlink Wn531G3 Firmware M31G3.V5030.200325
The WAVLINK Quantum D4G (WN531G3) running firmware version M31G3.V5030.200325 does not utilize anti-CSRF tokens, which, when combined with other issues (such as CVE-2022-35518), can lead to remote, unauthenticated command execution.
network
low complexity
wavlink CWE-352
8.8
2022-08-30 CVE-2022-37149 OS Command Injection vulnerability in Wavlink Wl-Wn575A3 Firmware Rpt75A3.V4300.201217
WAVLINK WL-WN575A3 RPT75A3.V4300.201217 was discovered to contain a command injection vulnerability when operating the file adm.cgi.
network
low complexity
wavlink CWE-78
critical
9.8