Search: "wavlink"

207 CVEs found

WAVLINK Quantum D4G (WL-WN531G3) running firmware versions M31G3.V5030.201204 and M31G3.V5030.200325 has an access control issue which allows unauthenticated attackers to download configuration data a...

Published: 2022-11-29
Products: 3
Vendors:
wavlink

An access control issue in the component /cgi-bin/ExportLogs.sh of Wavlink WL-WN530H4 M30H4.V5030.210121 allows unauthenticated attackers to download configuration data and log files and obtain admin ...

Published: 2023-02-03
Products: 2
Vendors:
wavlink

An access control issue in the component /cgi-bin/ExportLogs.sh of Wavlink WL-WN533A8 M33A8.V5030.190716 allows unauthenticated attackers to download configuration data and log files and obtain admin ...

Published: 2023-02-06
Products: 2
Vendors:
wavlink

An access control issue in Wavlink WL-WN530HG4 M30HG4.V5030.201217 allows unauthenticated attackers to download configuration data and log files and obtain admin credentials.

Published: 2023-02-06
Products: 2
Vendors:
wavlink

An issue was discovered in /cgi-bin/adm.cgi in WavLink WavRouter version RPT70HA1.x, allows attackers to force a factory reset via crafted payload.

Published: 2023-06-22
Products: 2
Vendors:
wavlink
CVE-2023-3380
4.7 MEDIUM

A vulnerability classified as critical has been found in Wavlink WN579X3 up to 20230615. Affected is an unknown function of the file /cgi-bin/adm.cgi of the component Ping Test. The manipulation of th...

Published: 2023-06-23
Products: 2
Vendors:
wavlink
CVE-2023-38861
9.8 CRITICAL

An issue in Wavlink WL_WNJ575A3 v.R75A3_V1410_220513 allows a remote attacker to execute arbitrary code via username parameter of the set_sys_adm function in adm.cgi.

Published: 2023-08-15
Products: 2
Vendors:
wavlink

An issue discovered in Wavlink QUANTUM D2G routers allows attackers to hijack TCP sessions which could lead to a denial of service.

Published: 2024-05-28
Products: 0
CVE-2024-38892
6.5 MEDIUM

An issue in Wavlink WN551K1 allows a remote attacker to obtain sensitive information via the ExportAllSettings.sh component.

Published: 2024-06-24
Products: 2
Vendors:
wavlink
CVE-2024-38894
5.3 MEDIUM

WAVLINK WN551K1 found a command injection vulnerability through the IP parameter of /cgi-bin/touchlist_sync.cgi.

Published: 2024-06-24
Products: 2
Vendors:
wavlink
CVE-2024-38895
5.3 MEDIUM

WAVLINK WN551K1'live_mfg.shtml enables attackers to obtain sensitive router information.

Published: 2024-06-24
Products: 2
Vendors:
wavlink
CVE-2024-38896
5.3 MEDIUM

WAVLINK WN551K1 found a command injection vulnerability through the start_hour parameter of /cgi-bin/nightled.cgi.

Published: 2024-06-24
Products: 2
Vendors:
wavlink
CVE-2024-38897
5.3 MEDIUM

WAVLINK WN551K1'live_check.shtml enables attackers to obtain sensitive router information.

Published: 2024-06-24
Products: 2
Vendors:
wavlink
CVE-2024-10193
4.7 MEDIUM

A vulnerability was found in WAVLINK WN530H4, WN530HG4 and WN572HG3 up to 20221028 and classified as critical. This issue affects the function ping_ddns of the file internet.cgi. The manipulation of t...

Published: 2024-10-20
Products: 6
Vendors:
wavlink

A vulnerability was found in WAVLINK WN530H4, WN530HG4 and WN572HG3 up to 20221028. It has been classified as critical. Affected is the function Goto_chidx of the file login.cgi of the component Front...

Published: 2024-10-20
Products: 6
Vendors:
wavlink

A vulnerability was found in WAVLINK WN530H4, WN530HG4 and WN572HG3 up to 20221028. It has been rated as critical. This issue affects the function set_ipv6 of the file firewall.cgi. The manipulation o...

Published: 2024-10-27
Products: 6
Vendors:
wavlink

A vulnerability classified as critical has been found in WAVLINK WN530H4, WN530HG4 and WN572HG3 up to 20221028. Affected is the function set_ipv6 of the file internet.cgi. The manipulation of the argu...

Published: 2024-10-27
Products: 6
Vendors:
wavlink
CVE-2024-54745
9.8 CRITICAL

WAVLINK WN701AE M01AE_V240305 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.

Published: 2024-12-06
Products: 2
Vendors:
wavlink
CVE-2024-54747
9.8 CRITICAL

WAVLINK WN531P3 202383 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.

Published: 2024-12-06
Products: 2
Vendors:
wavlink
CVE-2024-21797
9.1 CRITICAL

A command execution vulnerability exists in the adm.cgi set_TR069() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An att...

Published: 2025-01-14
Products: 2
Vendors:
wavlink