Vulnerabilities > Wavlink > Wn572Hg3 Firmware

DATE CVE VULNERABILITY TITLE RISK
2024-10-20 CVE-2024-10193 Command Injection vulnerability in Wavlink products
A vulnerability was found in WAVLINK WN530H4, WN530HG4 and WN572HG3 up to 20221028 and classified as critical.
network
low complexity
wavlink CWE-77
7.2
2024-10-20 CVE-2024-10194 Out-of-bounds Write vulnerability in Wavlink products
A vulnerability was found in WAVLINK WN530H4, WN530HG4 and WN572HG3 up to 20221028.
low complexity
wavlink CWE-787
8.8
2020-05-07 CVE-2020-10974 Missing Authentication for Critical Function vulnerability in Wavlink products
An issue was discovered affecting a backup feature where a crafted POST request returns the current configuration of the device in cleartext, including the administrator password.
network
low complexity
wavlink CWE-306
5.0
2020-05-07 CVE-2020-10972 Insufficiently Protected Credentials vulnerability in Wavlink products
An issue was discovered where a page is exposed that has the current administrator password in cleartext in the source code of the page.
network
low complexity
wavlink CWE-522
5.0