← Back

Wavlink

wavlink

203 CVEs • 76 products

Products (76)

Click to collapse
Toggle
Wavrouter App
wavrouter_app
Wl Wn579g3
wl-wn579g3
Wl Wn575a3
wl-wn575a3
Wl Wn530hg4
wl-wn530hg4
Wn531g3
wn531g3
Wn533a8
wn533a8
Wn531a6
wn531a6
Wn551k1
wn551k1
Wn535g3
wn535g3
Wn530h4
wn530h4
Wn57x93
wn57x93
Wn578a2
wn578a2
Wn579g3
wn579g3
Wn579x3
wn579x3
Wn530hg4
wn530hg4
Wn572hg3
wn572hg3
Wn575a4
wn575a4
Wl Wn531g3
wl-wn531g3
Wl Wn531p3
wl-wn531p3
Wl Wn535k2
wl-wn535k2
Wl Wn535k3
wl-wn535k3
Wl Wn579x3
wl-wn579x3
Wn572hp3
wn572hp3
Wn531p3
wn531p3
Wl Wn530h4
wl-wn530h4
Wl Wn533a8
wl-wn533a8
Wl Wn531ax2
wl-wn531ax2
Wn701ae
wn701ae
Wl Wn579a3
wl-wn579a3
Wn535k3
wn535k3
Wl Nu516u1
wl-nu516u1
Wl Wn578w2
wl-wn578w2
Wl Wn586x3a
wl-wn586x3a
Wl Wn579x3 C
wl-wn579x3-c
Wl Wn570ha1
wl-wn570ha1

CVEs (203)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Wavlink
1Wl Nu516u1 Firmware
Apr 29, 2026
Sep 22, 2025
2.0 LOW· v4
7.2 HIGH· v3
5.8 MEDIUM· v2
A security vulnerability has been detected in Wavlink WL-NU516U1 240425. This vulnerability affects the function sub_4012A0 of the file /cgi-bin/login.cgi. Such manipulation of the argument ipaddr leads to os command inj...Show more
A security vulnerability has been detected in Wavlink WL-NU516U1 240425. This vulnerability affects the function sub_4012A0 of the file /cgi-bin/login.cgi. Such manipulation of the argument ipaddr leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Wavlink
1Wl Wn578w2 Firmware
Apr 29, 2026
Sep 13, 2025
5.5 MEDIUM· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability was detected in Wavlink WL-WN578W2 221110. This impacts the function sub_404DBC of the file /cgi-bin/wireless.cgi. The manipulation of the argument macAddr results in os command injection. The attack can...Show more
A vulnerability was detected in Wavlink WL-WN578W2 221110. This impacts the function sub_404DBC of the file /cgi-bin/wireless.cgi. The manipulation of the argument macAddr results in os command injection. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Wavlink
1Wl Wn578w2 Firmware
Apr 29, 2026
Sep 13, 2025
5.5 MEDIUM· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A security vulnerability has been detected in Wavlink WL-WN578W2 221110. This affects the function sub_404850 of the file /cgi-bin/wireless.cgi. The manipulation of the argument delete_list leads to os command injection....Show more
A security vulnerability has been detected in Wavlink WL-WN578W2 221110. This affects the function sub_404850 of the file /cgi-bin/wireless.cgi. The manipulation of the argument delete_list leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Wavlink
1Wl Wn578w2 Firmware
Apr 29, 2026
Sep 12, 2025
2.1 LOW· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A vulnerability was identified in Wavlink WL-WN578W2 221110. This impacts the function sub_401340/sub_401BA4 of the file /cgi-bin/login.cgi. Such manipulation of the argument ipaddr leads to command injection. It is poss...Show more
A vulnerability was identified in Wavlink WL-WN578W2 221110. This impacts the function sub_401340/sub_401BA4 of the file /cgi-bin/login.cgi. Such manipulation of the argument ipaddr leads to command injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Wavlink
1Wl Wn578w2 Firmware
Apr 29, 2026
Sep 12, 2025
5.5 MEDIUM· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability was determined in Wavlink WL-WN578W2 221110. This affects the function sub_401C5C of the file firewall.cgi. This manipulation of the argument pingFrmWANFilterEnabled/blockSynFloodEnabled/blockPortScanEnab...Show more
A vulnerability was determined in Wavlink WL-WN578W2 221110. This affects the function sub_401C5C of the file firewall.cgi. This manipulation of the argument pingFrmWANFilterEnabled/blockSynFloodEnabled/blockPortScanEnabled/remoteManagementEnabled causes command injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Wavlink
1Wl Wn578w2 Firmware
Apr 29, 2026
Sep 12, 2025
5.5 MEDIUM· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability was found in Wavlink WL-WN578W2 221110. The impacted element is the function sub_409184 of the file /wizard_rep.shtml. The manipulation of the argument sel_EncrypTyp results in command injection. The atta...Show more
A vulnerability was found in Wavlink WL-WN578W2 221110. The impacted element is the function sub_409184 of the file /wizard_rep.shtml. The manipulation of the argument sel_EncrypTyp results in command injection. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Wavlink
1Wl Wn578w2 Firmware
Oct 2, 2025
Sep 12, 2025
5.5 MEDIUM· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability has been found in Wavlink WL-WN578W2 221110. The affected element is an unknown function of the file /sysinit.html. The manipulation of the argument newpass/confpass leads to weak password recovery. The a...Show more
A vulnerability has been found in Wavlink WL-WN578W2 221110. The affected element is an unknown function of the file /sysinit.html. The manipulation of the argument newpass/confpass leads to weak password recovery. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Wavlink
1Wl Wn578w2 Firmware
Oct 2, 2025
Sep 12, 2025
5.5 MEDIUM· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A flaw has been found in Wavlink WL-WN578W2 221110. Impacted is an unknown function of the file /live_online.shtml. Executing manipulation can lead to information disclosure. The attack can be executed remotely. The expl...Show more
A flaw has been found in Wavlink WL-WN578W2 221110. Impacted is an unknown function of the file /live_online.shtml. Executing manipulation can lead to information disclosure. The attack can be executed remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Wavlink
1Wl Wn535k3 Firmware
Sep 4, 2025
Sep 2, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Wavlink WN535K3 20191010 was found to contain a command injection vulnerability in the set_sys_adm function via the username parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted requ...Show more
Wavlink WN535K3 20191010 was found to contain a command injection vulnerability in the set_sys_adm function via the username parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.Show less
1Wavlink
1Wl Wn535k3 Firmware
Sep 4, 2025
Sep 2, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Wavlink WN535K3 20191010 was found to contain a command injection vulnerability in the set_sys_cmd function via the command parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted reque...Show more
Wavlink WN535K3 20191010 was found to contain a command injection vulnerability in the set_sys_cmd function via the command parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.Show less
1Wavlink
1Wl Wn531p3 Firmware
Sep 4, 2025
Sep 2, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Wavlink AC1200 with firmware versions M32A3_V1410_230602 and M32A3_V1410_240222 are vulnerable to a post-authentication command injection while resetting the password. This vulnerability is specifically found within the...Show more
Wavlink AC1200 with firmware versions M32A3_V1410_230602 and M32A3_V1410_240222 are vulnerable to a post-authentication command injection while resetting the password. This vulnerability is specifically found within the "set_sys_adm" function of the "adm.cgi" binary, and is due to improper santization of the user provided "newpass" fieldShow less
1Wavlink
1Wl Nu516u1 Firmware
Apr 29, 2026
Aug 19, 2025
2.1 LOW· v4
9.8 CRITICAL· v3
6.5 MEDIUM· v2
A vulnerability was determined in Wavlink WL-NU516U1 M16U1_V240425. This impacts the function sub_4032E4 of the file /cgi-bin/wireless.cgi. This manipulation of the argument Guest_ssid causes command injection. The attac...Show more
A vulnerability was determined in Wavlink WL-NU516U1 M16U1_V240425. This impacts the function sub_4032E4 of the file /cgi-bin/wireless.cgi. This manipulation of the argument Guest_ssid causes command injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.Show less
1Wavlink
1Wn535k3 Firmware
Oct 3, 2025
Jul 14, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Wavlink WN535K3 20191010 was found to contain a command injection vulnerability in the set_sys_adm function via the newpass parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted reque...Show more
Wavlink WN535K3 20191010 was found to contain a command injection vulnerability in the set_sys_adm function via the newpass parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.Show less
1Wavlink
1Wl Wn579a3 Firmware
May 30, 2025
May 20, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A command injection vulnerability in the component /cgi-bin/firewall.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commands via a crafted input.
1Wavlink
1Wl Wn579a3 Firmware
May 30, 2025
May 20, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A command injection vulnerability in the component /cgi-bin/adm.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commands via a crafted input.
1Wavlink
1Wl Wn579a3 Firmware
May 30, 2025
May 20, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A command injection vulnerability in the component /cgi-bin/qos.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commands via a crafted input.
1Wavlink
1Wl Wn530h4 Firmware
Jun 13, 2025
May 2, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Wavlink WL-WN530H4 20220801 was found to contain a command injection vulnerability in the ping_test function of the adm.cgi via the pingIp parameter. This vulnerability allows attackers to execute arbitrary commands via...Show more
Wavlink WL-WN530H4 20220801 was found to contain a command injection vulnerability in the ping_test function of the adm.cgi via the pingIp parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.Show less
1Wavlink
1Wl Wn575a3 Firmware
Oct 7, 2025
Feb 11, 2025
N/A· v4
5.1 MEDIUM· v3
N/A· v2
Multiple buffer overflow vulnerabilities in Wavlink WL-WN575A3 RPT75A3.V4300, which are caused by not performing strict length checks on user-controlled data. By successfully exploiting the vulnerabilities, attackers can...Show more
Multiple buffer overflow vulnerabilities in Wavlink WL-WN575A3 RPT75A3.V4300, which are caused by not performing strict length checks on user-controlled data. By successfully exploiting the vulnerabilities, attackers can crash the remote devices or execute arbitrary commands without any authorization verification.Show less
1Wavlink
1Wl Wn533a8 Firmware
Nov 3, 2025
Jan 14, 2025
N/A· v4
7.2 HIGH· v3
N/A· v2
Multiple buffer overflow vulnerabilities exist in the qos.cgi qos_settings() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can m...Show more
Multiple buffer overflow vulnerabilities exist in the qos.cgi qos_settings() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A buffer overflow vulnerability exists in the `sel_mode` POST parameter.Show less
1Wavlink
1Wl Wn533a8 Firmware
Nov 3, 2025
Jan 14, 2025
N/A· v4
7.2 HIGH· v3
N/A· v2
Multiple buffer overflow vulnerabilities exist in the qos.cgi qos_settings() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can m...Show more
Multiple buffer overflow vulnerabilities exist in the qos.cgi qos_settings() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A buffer overflow vulnerability exists in the `qos_dat` POST parameter.Show less