Vulnerabilities > Wavlink > Wn535G3 Firmware > High

DATE CVE VULNERABILITY TITLE RISK
2022-08-10 CVE-2022-35517 Unspecified vulnerability in Wavlink products
WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 adm.cgi has no filtering on parameters: web_pskValue, wl_Method, wlan_ssid, EncrypType, rwan_ip, rwan_mask, rwan_gateway, ppp_username, ppp_passwd and ppp_setver, which leads to command injection in page /wizard_router_mesh.shtml.
network
low complexity
wavlink
8.8
2022-07-25 CVE-2022-34576 Unspecified vulnerability in Wavlink Wn535G3 Firmware M35G3R.V5030.180927
A vulnerability in /cgi-bin/ExportAllSettings.sh of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to execute arbitrary code via a crafted POST request.
network
low complexity
wavlink
7.5
2022-06-14 CVE-2022-31845 Exposure of Resource to Wrong Sphere vulnerability in Wavlink Wn535G3 Firmware M35G3R.V5030.180927
A vulnerability in live_check.shtml of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to obtain sensitive router information via execution of the exec cmd function.
network
low complexity
wavlink CWE-668
7.5
2022-06-14 CVE-2022-31846 Exposure of Resource to Wrong Sphere vulnerability in Wavlink Wn535G3 Firmware M35G3R.V5030.180927
A vulnerability in live_mfg.shtml of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to obtain sensitive router information via execution of the exec cmd function.
network
low complexity
wavlink CWE-668
7.5
2020-05-07 CVE-2020-10974 Missing Authentication for Critical Function vulnerability in Wavlink products
An issue was discovered affecting a backup feature where a crafted POST request returns the current configuration of the device in cleartext, including the administrator password.
network
low complexity
wavlink CWE-306
7.5
2020-04-27 CVE-2020-12266 Missing Authentication for Critical Function vulnerability in Wavlink products
An issue was discovered where there are multiple externally accessible pages that do not require any sort of authentication, and store system information for internal usage.
network
low complexity
wavlink CWE-306
7.5