Vulnerabilities > Wavlink > WL Wn530Hg4 Firmware

DATE CVE VULNERABILITY TITLE RISK
2023-02-06 CVE-2022-48166 Missing Authorization vulnerability in Wavlink Wl-Wn530Hg4 Firmware M30Hg4.V5030.201217
An access control issue in Wavlink WL-WN530HG4 M30HG4.V5030.201217 allows unauthenticated attackers to download configuration data and log files and obtain admin credentials.
network
low complexity
wavlink CWE-862
7.5
2022-07-20 CVE-2022-34045 Use of Hard-coded Credentials vulnerability in Wavlink Wl-Wn530Hg4 Firmware M30Hg4.V5030.191116
Wavlink WN530HG4 M30HG4.V5030.191116 was discovered to contain a hardcoded encryption/decryption key for its configuration files at /etc_ro/lighttpd/www/cgi-bin/ExportAllSettings.sh.
network
low complexity
wavlink CWE-798
critical
9.8
2022-07-20 CVE-2022-34047 Exposure of Resource to Wrong Sphere vulnerability in Wavlink Wl-Wn530Hg4 Firmware M30Hg4.V5030.191116
An access control issue in Wavlink WN530HG4 M30HG4.V5030.191116 allows attackers to obtain usernames and passwords via view-source:http://IP_ADDRESS/set_safety.shtml?r=52300 and searching for [var syspasswd].
network
low complexity
wavlink CWE-668
7.5
2022-07-20 CVE-2022-34049 Files or Directories Accessible to External Parties vulnerability in Wavlink Wl-Wn530Hg4 Firmware M30Hg4.V5030.191116
An access control issue in Wavlink WN530HG4 M30HG4.V5030.191116 allows unauthenticated attackers to download log files and configuration data.
network
low complexity
wavlink CWE-552
5.3
2020-07-01 CVE-2020-15490 Classic Buffer Overflow vulnerability in Wavlink Wl-Wn530Hg4 Firmware M30Hg4.V5030.191116
An issue was discovered on Wavlink WL-WN530HG4 M30HG4.V5030.191116 devices.
network
low complexity
wavlink CWE-120
critical
9.8
2020-07-01 CVE-2020-15489 OS Command Injection vulnerability in Wavlink Wl-Wn530Hg4 Firmware M30Hg4.V5030.191116
An issue was discovered on Wavlink WL-WN530HG4 M30HG4.V5030.191116 devices.
network
low complexity
wavlink CWE-78
critical
9.8
2020-05-07 CVE-2020-10971 Improper Input Validation vulnerability in Wavlink products
An issue was discovered on Wavlink Jetstream devices where a crafted POST request can be sent to adm.cgi that will result in the execution of the supplied command if there is an active session at the same time.
network
low complexity
wavlink CWE-20
8.8
2020-04-27 CVE-2020-12266 Missing Authentication for Critical Function vulnerability in Wavlink products
An issue was discovered where there are multiple externally accessible pages that do not require any sort of authentication, and store system information for internal usage.
network
low complexity
wavlink CWE-306
7.5