← Back

Wavlink

wavlink

203 CVEs • 76 products

Products (76)

Click to collapse
Toggle
Wavrouter App
wavrouter_app
Wl Wn579g3
wl-wn579g3
Wl Wn575a3
wl-wn575a3
Wl Wn530hg4
wl-wn530hg4
Wn531g3
wn531g3
Wn533a8
wn533a8
Wn531a6
wn531a6
Wn551k1
wn551k1
Wn535g3
wn535g3
Wn530h4
wn530h4
Wn57x93
wn57x93
Wn578a2
wn578a2
Wn579g3
wn579g3
Wn579x3
wn579x3
Wn530hg4
wn530hg4
Wn572hg3
wn572hg3
Wn575a4
wn575a4
Wl Wn531g3
wl-wn531g3
Wl Wn531p3
wl-wn531p3
Wl Wn535k2
wl-wn535k2
Wl Wn535k3
wl-wn535k3
Wl Wn579x3
wl-wn579x3
Wn572hp3
wn572hp3
Wn531p3
wn531p3
Wl Wn530h4
wl-wn530h4
Wl Wn533a8
wl-wn533a8
Wl Wn531ax2
wl-wn531ax2
Wn701ae
wn701ae
Wl Wn579a3
wl-wn579a3
Wn535k3
wn535k3
Wl Nu516u1
wl-nu516u1
Wl Wn578w2
wl-wn578w2
Wl Wn586x3a
wl-wn586x3a
Wl Wn579x3 C
wl-wn579x3-c
Wl Wn570ha1
wl-wn570ha1

CVEs (203)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Wavlink
5Wn530h4 Firmware
Wn531p3 FirmwareWn533a8 Firmware+2 more
Nov 21, 2024
Aug 10, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 firewall.cgi has no filtering on parameter add_mac, which leads to command injection in page /cli_black_list.shtml.
1Wavlink
5Wn530h4 Firmware
Wn531p3 FirmwareWn533a8 Firmware+2 more
Oct 20, 2025
Aug 10, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 nas.cgi has no filtering on parameters: User1Passwd and User1, which leads to command injection in page /nas_disk.shtml.
1Wavlink
5Wn530h4 Firmware
Wn531p3 FirmwareWn533a8 Firmware+2 more
Nov 21, 2024
Aug 10, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 adm.cgi has no filtering on parameters: web_pskValue, wl_Method, wlan_ssid, EncrypType, rwan_ip, rwan_mask, rwan_gateway, ppp_username, ppp_passwd and ppp_setver, whic...Show more
WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 adm.cgi has no filtering on parameters: web_pskValue, wl_Method, wlan_ssid, EncrypType, rwan_ip, rwan_mask, rwan_gateway, ppp_username, ppp_passwd and ppp_setver, which leads to command injection in page /wizard_router_mesh.shtml.Show less
1Wavlink
1Wn535g3 Firmware
Nov 21, 2024
Jul 25, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A vulnerability in adm.cgi of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to execute arbitrary code via a crafted POST request.
1Wavlink
1Wn535g3 Firmware
Nov 21, 2024
Jul 25, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
A vulnerability in /cgi-bin/ExportAllSettings.sh of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to execute arbitrary code via a crafted POST request.
1Wavlink
1Wifi Repeater Firmware
Nov 21, 2024
Jul 25, 2022
N/A· v4
5.7 MEDIUM· v3
N/A· v2
An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to obtain the key information of the device via accessing fctest.shtml.
1Wavlink
1Wifi Repeater Firmware
Nov 21, 2024
Jul 25, 2022
N/A· v4
5.7 MEDIUM· v3
N/A· v2
An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to obtain the key information of the device via accessing Tftpd32.ini.
1Wavlink
1Wifi Repeater Firmware
Nov 21, 2024
Jul 25, 2022
N/A· v4
6.3 MEDIUM· v3
N/A· v2
An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to arbitrarily configure device settings via accessing the page mb_wifibasic.shtml.
1Wavlink
1Wifi Repeater Firmware
Nov 21, 2024
Jul 25, 2022
N/A· v4
5.7 MEDIUM· v3
N/A· v2
An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to obtain the telnet password via accessing the page tftp.txt.
1Wavlink
1Wifi Repeater Firmware
Nov 21, 2024
Jul 25, 2022
N/A· v4
8.0 HIGH· v3
N/A· v2
An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to obtain the system key information and execute arbitrary commands via accessing the page syslog.shtml.
1Wavlink
1Wl Wn579x3 Firmware
Nov 21, 2024
Jul 25, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
WAVLINK WN579 X3 M79X3.V5030.191012/M79X3.V5030.191012 contains an information leak which allows attackers to obtain the key information via accessing the messages.txt page.
1Wavlink
1Wl Wn530hg4 Firmware
Nov 21, 2024
Jul 20, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An access control issue in Wavlink WN530HG4 M30HG4.V5030.191116 allows unauthenticated attackers to download log files and configuration data.
1Wavlink
1Wn533a8 Firmware
Nov 21, 2024
Jul 20, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Wavlink WN533A8 M33A8.V5030.190716 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the login_page parameter.
1Wavlink
1Wl Wn530hg4 Firmware
Nov 21, 2024
Jul 20, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
An access control issue in Wavlink WN530HG4 M30HG4.V5030.191116 allows attackers to obtain usernames and passwords via view-source:http://IP_ADDRESS/set_safety.shtml?r=52300 and searching for [var syspasswd].
1Wavlink
1Wn533a8 Firmware
Nov 21, 2024
Jul 20, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
An access control issue in Wavlink WN533A8 M33A8.V5030.190716 allows attackers to obtain usernames and passwords via view-source:http://IP_ADDRESS/sysinit.shtml?r=52300 and searching for [logincheck(user);].
1Wavlink
1Wl Wn530hg4 Firmware
Nov 21, 2024
Jul 20, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Wavlink WN530HG4 M30HG4.V5030.191116 was discovered to contain a hardcoded encryption/decryption key for its configuration files at /etc_ro/lighttpd/www/cgi-bin/ExportAllSettings.sh.
1Wavlink
2Wl Wn535k2 Firmware
Wl Wn535k3 Firmware
Jan 14, 2025
Jul 20, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A vulnerability was found in WAVLINK WN535K2 and WN535K3 and classified as critical. This issue affects some unknown processing of the file /cgi-bin/touchlist_sync.cgi. The manipulation of the argument IP leads to os com...Show more
A vulnerability was found in WAVLINK WN535K2 and WN535K3 and classified as critical. This issue affects some unknown processing of the file /cgi-bin/touchlist_sync.cgi. The manipulation of the argument IP leads to os command injection. The exploit has been disclosed to the public and may be used.Show less
1Wavlink
2Wl Wn535k2 Firmware
Wl Wn535k3 Firmware
Nov 21, 2024
Jul 20, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A vulnerability has been found in WAVLINK WN535K2 and WN535K3 and classified as critical. This vulnerability affects unknown code of the file /cgi-bin/nightled.cgi. The manipulation of the argument start_hour leads to os...Show more
A vulnerability has been found in WAVLINK WN535K2 and WN535K3 and classified as critical. This vulnerability affects unknown code of the file /cgi-bin/nightled.cgi. The manipulation of the argument start_hour leads to os command injection. The exploit has been disclosed to the public and may be used.Show less
1Wavlink
2Wl Wn535k2 Firmware
Wl Wn535k3 Firmware
Nov 21, 2024
Jul 20, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A vulnerability, which was classified as critical, was found in WAVLINK WN535K2 and WN535K3. This affects an unknown part of the file /cgi-bin/mesh.cgi?page=upgrade. The manipulation of the argument key leads to os comma...Show more
A vulnerability, which was classified as critical, was found in WAVLINK WN535K2 and WN535K3. This affects an unknown part of the file /cgi-bin/mesh.cgi?page=upgrade. The manipulation of the argument key leads to os command injection. The exploit has been disclosed to the public and may be used.Show less
1Wavlink
1Wl Wn575a3 Firmware
Nov 21, 2024
Jul 7, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Wavlink WL-WN575A3 RPT75A3.V4300.201217 was discovered to contain a command injection vulnerability via the function obtw. This vulnerability allows attackers to execute arbitrary commands via a crafted POST request.