Search: "wavlink"

207 CVEs found

CVE-2024-39803
9.1 CRITICAL

Multiple buffer overflow vulnerabilities exist in the qos.cgi qos_settings() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflo...

Published: 2025-01-14
Products: 2
Vendors:
wavlink
CVE-2025-25528
5.1 MEDIUM

Multiple buffer overflow vulnerabilities in Wavlink WL-WN575A3 RPT75A3.V4300, which are caused by not performing strict length checks on user-controlled data. By successfully exploiting the vulnerabil...

Published: 2025-02-11
Products: 2
Vendors:
wavlink
CVE-2025-44868
9.8 CRITICAL

Wavlink WL-WN530H4 20220801 was found to contain a command injection vulnerability in the ping_test function of the adm.cgi via the pingIp parameter. This vulnerability allows attackers to execute arb...

Published: 2025-05-02
Products: 2
Vendors:
wavlink
CVE-2025-44881
9.8 CRITICAL

A command injection vulnerability in the component /cgi-bin/qos.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commands via a crafted input.

Published: 2025-05-20
Products: 2
Vendors:
wavlink
CVE-2025-44880
9.8 CRITICAL

A command injection vulnerability in the component /cgi-bin/adm.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commands via a crafted input.

Published: 2025-05-20
Products: 2
Vendors:
wavlink
CVE-2025-44882
9.8 CRITICAL

A command injection vulnerability in the component /cgi-bin/firewall.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commands via a crafted input.

Published: 2025-05-20
Products: 2
Vendors:
wavlink
CVE-2025-5408
9.8 CRITICAL

A vulnerability was found in WAVLINK QUANTUM D2G, QUANTUM D3G, WL-WN530G3A, WL-WN530HG3, WL-WN532A3 and WL-WN576K1 up to V1410_240222 and classified as critical. Affected by this issue is the function...

Published: 2025-06-01
Products: 0
CVE-2025-50756
9.8 CRITICAL

Wavlink WN535K3 20191010 was found to contain a command injection vulnerability in the set_sys_adm function via the newpass parameter. This vulnerability allows attackers to execute arbitrary commands...

Published: 2025-07-14
Products: 2
Vendors:
wavlink
CVE-2025-9149
6.3 MEDIUM

A vulnerability was determined in Wavlink WL-NU516U1 M16U1_V240425. This impacts the function sub_4032E4 of the file /cgi-bin/wireless.cgi. This manipulation of the argument Guest_ssid causes command ...

Published: 2025-08-19
Products: 2
Vendors:
wavlink
CVE-2024-48705
6.5 MEDIUM

Wavlink AC1200 with firmware versions M32A3_V1410_230602 and M32A3_V1410_240222 are vulnerable to a post-authentication command injection while resetting the password. This vulnerability is specifical...

Published: 2025-09-02
Products: 3
Vendors:
wavlink
CVE-2025-50755
6.5 MEDIUM

Wavlink WN535K3 20191010 was found to contain a command injection vulnerability in the set_sys_cmd function via the command parameter. This vulnerability allows attackers to execute arbitrary commands...

Published: 2025-09-02
Products: 2
Vendors:
wavlink
CVE-2025-50757
6.5 MEDIUM

Wavlink WN535K3 20191010 was found to contain a command injection vulnerability in the set_sys_adm function via the username parameter. This vulnerability allows attackers to execute arbitrary command...

Published: 2025-09-02
Products: 2
Vendors:
wavlink
CVE-2025-10321
5.3 MEDIUM

A flaw has been found in Wavlink WL-WN578W2 221110. Impacted is an unknown function of the file /live_online.shtml. Executing manipulation can lead to information disclosure. The attack can be execute...

Published: 2025-09-12
Products: 2
Vendors:
wavlink
CVE-2025-10322
5.3 MEDIUM

A vulnerability has been found in Wavlink WL-WN578W2 221110. The affected element is an unknown function of the file /sysinit.html. The manipulation of the argument newpass/confpass leads to weak pass...

Published: 2025-09-12
Products: 2
Vendors:
wavlink

A vulnerability was found in Wavlink WL-WN578W2 221110. The impacted element is the function sub_409184 of the file /wizard_rep.shtml. The manipulation of the argument sel_EncrypTyp results in command...

Published: 2025-09-12
Products: 2
Vendors:
wavlink

A vulnerability was determined in Wavlink WL-WN578W2 221110. This affects the function sub_401C5C of the file firewall.cgi. This manipulation of the argument pingFrmWANFilterEnabled/blockSynFloodEnabl...

Published: 2025-09-12
Products: 2
Vendors:
wavlink
CVE-2025-10325
6.3 MEDIUM

A vulnerability was identified in Wavlink WL-WN578W2 221110. This impacts the function sub_401340/sub_401BA4 of the file /cgi-bin/login.cgi. Such manipulation of the argument ipaddr leads to command i...

Published: 2025-09-12
Products: 2
Vendors:
wavlink

A security vulnerability has been detected in Wavlink WL-WN578W2 221110. This affects the function sub_404850 of the file /cgi-bin/wireless.cgi. The manipulation of the argument delete_list leads to o...

Published: 2025-09-13
Products: 2
Vendors:
wavlink

A vulnerability was detected in Wavlink WL-WN578W2 221110. This impacts the function sub_404DBC of the file /cgi-bin/wireless.cgi. The manipulation of the argument macAddr results in os command inject...

Published: 2025-09-13
Products: 2
Vendors:
wavlink
CVE-2025-10775
4.7 MEDIUM

A security vulnerability has been detected in Wavlink WL-NU516U1 240425. This vulnerability affects the function sub_4012A0 of the file /cgi-bin/login.cgi. Such manipulation of the argument ipaddr lea...

Published: 2025-09-22
Products: 2
Vendors:
wavlink