Vulnerabilities > Wavlink > Wn530H4 Firmware > High

DATE CVE VULNERABILITY TITLE RISK
2024-10-20 CVE-2024-10193 Command Injection vulnerability in Wavlink products
A vulnerability was found in WAVLINK WN530H4, WN530HG4 and WN572HG3 up to 20221028 and classified as critical.
network
low complexity
wavlink CWE-77
7.2
2024-10-20 CVE-2024-10194 Out-of-bounds Write vulnerability in Wavlink products
A vulnerability was found in WAVLINK WN530H4, WN530HG4 and WN572HG3 up to 20221028.
low complexity
wavlink CWE-787
8.8
2022-08-10 CVE-2022-35517 Unspecified vulnerability in Wavlink products
WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 adm.cgi has no filtering on parameters: web_pskValue, wl_Method, wlan_ssid, EncrypType, rwan_ip, rwan_mask, rwan_gateway, ppp_username, ppp_passwd and ppp_setver, which leads to command injection in page /wizard_router_mesh.shtml.
network
low complexity
wavlink
8.8
2020-10-02 CVE-2020-12126 Improper Authentication vulnerability in Wavlink Wn530H4 Firmware M30H4.V5030.190403
Multiple authentication bypass vulnerabilities in the /cgi-bin/ endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allow an attacker to leak router settings, change configuration variables, and cause denial of service via an unauthenticated endpoint.
network
low complexity
wavlink CWE-287
7.5
2020-10-02 CVE-2020-12123 Cross-Site Request Forgery (CSRF) vulnerability in Wavlink Wn530H4 Firmware M30H4.V5030.190403
CSRF vulnerabilities in the /cgi-bin/ directory of the WAVLINK WN530H4 M30H4.V5030.190403 allow an attacker to remotely access router endpoints, because these endpoints do not contain CSRF tokens.
network
wavlink CWE-352
7.8