Vulnerabilities > Wavlink > Critical

DATE CVE VULNERABILITY TITLE RISK
2022-04-07 CVE-2022-23900 OS Command Injection vulnerability in Wavlink Wl-Wn531P3 Firmware M31G3.V5030.201204
A command injection vulnerability in the API of the Wavlink WL-WN531P3 router, version M31G3.V5030.201204, allows an attacker to achieve unauthorized remote code execution via a malicious POST request through /cgi-bin/adm.cgi.
network
low complexity
wavlink CWE-78
critical
9.8
2021-02-09 CVE-2020-13117 Command Injection vulnerability in Wavlink Wn575A4 Firmware and Wn579X3 Firmware
Wavlink WN575A4 and WN579X3 devices through 2020-05-15 allow unauthenticated remote users to inject commands via the key parameter in a login request.
network
low complexity
wavlink CWE-77
critical
10.0
2020-10-02 CVE-2020-12125 Classic Buffer Overflow vulnerability in Wavlink Wn530H4 Firmware M30H4.V5030.190403
A remote buffer overflow vulnerability in the /cgi-bin/makeRequest.cgi endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to execute arbitrary machine instructions as root without authentication.
network
low complexity
wavlink CWE-120
critical
10.0
2020-10-02 CVE-2020-12124 OS Command Injection vulnerability in Wavlink Wn530H4 Firmware M30H4.V5030.190403
A remote command-line injection vulnerability in the /cgi-bin/live_api.cgi endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to execute arbitrary Linux commands as root without authentication.
network
low complexity
wavlink CWE-78
critical
10.0
2020-07-01 CVE-2020-15490 Classic Buffer Overflow vulnerability in Wavlink Wl-Wn530Hg4 Firmware M30Hg4.V5030.191116
An issue was discovered on Wavlink WL-WN530HG4 M30HG4.V5030.191116 devices.
network
low complexity
wavlink CWE-120
critical
10.0
2020-07-01 CVE-2020-15489 Injection vulnerability in Wavlink Wl-Wn530Hg4 Firmware M30Hg4.V5030.191116
An issue was discovered on Wavlink WL-WN530HG4 M30HG4.V5030.191116 devices.
network
low complexity
wavlink CWE-74
critical
10.0
2020-05-07 CVE-2020-10971 Improper Input Validation vulnerability in Wavlink products
An issue was discovered on Wavlink Jetstream devices where a crafted POST request can be sent to adm.cgi that will result in the execution of the supplied command if there is an active session at the same time.
network
wavlink CWE-20
critical
9.3