← Back

Wavlink

wavlink

203 CVEs • 76 products

Products (76)

Click to collapse
Toggle
Wavrouter App
wavrouter_app
Wl Wn579g3
wl-wn579g3
Wl Wn575a3
wl-wn575a3
Wl Wn530hg4
wl-wn530hg4
Wn531g3
wn531g3
Wn533a8
wn533a8
Wn531a6
wn531a6
Wn551k1
wn551k1
Wn535g3
wn535g3
Wn530h4
wn530h4
Wn57x93
wn57x93
Wn578a2
wn578a2
Wn579g3
wn579g3
Wn579x3
wn579x3
Wn530hg4
wn530hg4
Wn572hg3
wn572hg3
Wn575a4
wn575a4
Wl Wn531g3
wl-wn531g3
Wl Wn531p3
wl-wn531p3
Wl Wn535k2
wl-wn535k2
Wl Wn535k3
wl-wn535k3
Wl Wn579x3
wl-wn579x3
Wn572hp3
wn572hp3
Wn531p3
wn531p3
Wl Wn530h4
wl-wn530h4
Wl Wn533a8
wl-wn533a8
Wl Wn531ax2
wl-wn531ax2
Wn701ae
wn701ae
Wl Wn579a3
wl-wn579a3
Wn535k3
wn535k3
Wl Nu516u1
wl-nu516u1
Wl Wn578w2
wl-wn578w2
Wl Wn586x3a
wl-wn586x3a
Wl Wn579x3 C
wl-wn579x3-c
Wl Wn570ha1
wl-wn570ha1

CVEs (203)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Wavlink
1Wn531p3 Firmware
Oct 3, 2025
Dec 6, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
WAVLINK WN531P3 202383 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.
1Wavlink
1Wn701ae Firmware
Oct 3, 2025
Dec 6, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
WAVLINK WN701AE M01AE_V240305 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.
1Wavlink
3Wn530h4 Firmware
Wn530hg4 FirmwareWn572hg3 Firmware
Nov 13, 2024
Oct 27, 2024
8.6 HIGH· v4
7.2 HIGH· v3
8.3 HIGH· v2
A vulnerability classified as critical has been found in WAVLINK WN530H4, WN530HG4 and WN572HG3 up to 20221028. Affected is the function set_ipv6 of the file internet.cgi. The manipulation of the argument IPv6OpMode/IPv6...Show more
A vulnerability classified as critical has been found in WAVLINK WN530H4, WN530HG4 and WN572HG3 up to 20221028. Affected is the function set_ipv6 of the file internet.cgi. The manipulation of the argument IPv6OpMode/IPv6IPAddr/IPv6WANIPAddr/IPv6GWAddr leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Wavlink
3Wn530h4 Firmware
Wn530hg4 FirmwareWn572hg3 Firmware
Nov 13, 2024
Oct 27, 2024
8.6 HIGH· v4
7.2 HIGH· v3
8.3 HIGH· v2
A vulnerability was found in WAVLINK WN530H4, WN530HG4 and WN572HG3 up to 20221028. It has been rated as critical. This issue affects the function set_ipv6 of the file firewall.cgi. The manipulation of the argument dhcpG...Show more
A vulnerability was found in WAVLINK WN530H4, WN530HG4 and WN572HG3 up to 20221028. It has been rated as critical. This issue affects the function set_ipv6 of the file firewall.cgi. The manipulation of the argument dhcpGateway leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Wavlink
3Wn530h4 Firmware
Wn530hg4 FirmwareWn572hg3 Firmware
Oct 23, 2024
Oct 20, 2024
8.7 HIGH· v4
8.8 HIGH· v3
8.3 HIGH· v2
A vulnerability was found in WAVLINK WN530H4, WN530HG4 and WN572HG3 up to 20221028. It has been classified as critical. Affected is the function Goto_chidx of the file login.cgi of the component Front-End Authentication...Show more
A vulnerability was found in WAVLINK WN530H4, WN530HG4 and WN572HG3 up to 20221028. It has been classified as critical. Affected is the function Goto_chidx of the file login.cgi of the component Front-End Authentication Page. The manipulation of the argument wlanUrl leads to stack-based buffer overflow. The attack can only be initiated within the local network. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Wavlink
3Wn530h4 Firmware
Wn530hg4 FirmwareWn572hg3 Firmware
Oct 23, 2024
Oct 20, 2024
5.1 MEDIUM· v4
7.2 HIGH· v3
5.8 MEDIUM· v2
A vulnerability was found in WAVLINK WN530H4, WN530HG4 and WN572HG3 up to 20221028 and classified as critical. This issue affects the function ping_ddns of the file internet.cgi. The manipulation of the argument DDNS lea...Show more
A vulnerability was found in WAVLINK WN530H4, WN530HG4 and WN572HG3 up to 20221028 and classified as critical. This issue affects the function ping_ddns of the file internet.cgi. The manipulation of the argument DDNS leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Wavlink
1Wn551k1 Firmware
Jun 6, 2025
Jun 24, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
WAVLINK WN551K1'live_check.shtml enables attackers to obtain sensitive router information.
1Wavlink
1Wn551k1 Firmware
Jun 6, 2025
Jun 24, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
WAVLINK WN551K1 found a command injection vulnerability through the start_hour parameter of /cgi-bin/nightled.cgi.
1Wavlink
1Wn551k1 Firmware
Jun 6, 2025
Jun 24, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
WAVLINK WN551K1'live_mfg.shtml enables attackers to obtain sensitive router information.
1Wavlink
1Wn551k1 Firmware
Jun 6, 2025
Jun 24, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
WAVLINK WN551K1 found a command injection vulnerability through the IP parameter of /cgi-bin/touchlist_sync.cgi.
1Wavlink
1Wn551k1 Firmware
Jun 6, 2025
Jun 24, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue in Wavlink WN551K1 allows a remote attacker to obtain sensitive information via the ExportAllSettings.sh component.
1Wavlink
1Wl Wn575a3 Firmware
Nov 21, 2024
Aug 15, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue in Wavlink WL_WNJ575A3 v.R75A3_V1410_220513 allows a remote attacker to execute arbitrary code via username parameter of the set_sys_adm function in adm.cgi.
1Wavlink
1Wl Wn531ax2 Firmware
Dec 4, 2024
Jun 30, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
Improper neutralization of special elements in WL-WN531AX2 firmware versions prior to 2023526 allows an attacker with an administrative privilege to execute OS commands with the root privilege.
1Wavlink
1Wl Wn531ax2 Firmware
Nov 21, 2024
Jun 30, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
WL-WN531AX2 firmware versions prior to 2023526 allows an attacker with an administrative privilege to upload arbitrary files and execute OS commands with the root privilege.
1Wavlink
1Wl Wn531ax2 Firmware
Nov 21, 2024
Jun 30, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Improper authentication vulnerability in WL-WN531AX2 firmware versions prior to 2023526 allows a network-adjacent attacker to obtain a password for the wireless network.
1Wavlink
1Wl Wn531ax2 Firmware
Nov 21, 2024
Jun 30, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
Exposure of resource to wrong sphere issue exists in WL-WN531AX2 firmware versions prior to 2023526, which may allow a network-adjacent attacker to use functions originally available after login without logging in.
1Wavlink
1Wl Wn531ax2 Firmware
Nov 27, 2024
Jun 30, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
Client-side enforcement of server-side security issue exists in WL-WN531AX2 firmware versions prior to 2023526, which may allow an attacker with an administrative privilege to execute OS commands with the root privilege.
1Wavlink
1Wn579x3 Firmware
Nov 21, 2024
Jun 23, 2023
N/A· v4
9.8 CRITICAL· v3
5.8 MEDIUM· v2
A vulnerability classified as critical has been found in Wavlink WN579X3 up to 20230615. Affected is an unknown function of the file /cgi-bin/adm.cgi of the component Ping Test. The manipulation of the argument pingIp le...Show more
A vulnerability classified as critical has been found in Wavlink WN579X3 up to 20230615. Affected is an unknown function of the file /cgi-bin/adm.cgi of the component Ping Test. The manipulation of the argument pingIp leads to injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-232236. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Wavlink
1Wavrouter App
Dec 6, 2024
Jun 22, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in /cgi-bin/adm.cgi in WavLink WavRouter version RPT70HA1.x, allows attackers to force a factory reset via crafted payload.
1Wavlink
1Wl Wn530hg4 Firmware
Mar 25, 2025
Feb 6, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An access control issue in Wavlink WL-WN530HG4 M30HG4.V5030.201217 allows unauthenticated attackers to download configuration data and log files and obtain admin credentials.