wavlink

210 tracked vulnerabilities.

CVE-2025-10324 HIGH
Wavlink WL-WN578W2 221110 - OS Command Injection via firewall.cgi Parameter Manipulation
Sep 12, 2025
CVSS 7.3
EPSS 0.01
CVE-2025-10323 HIGH
Wavlink WL-WN578W2 221110 - OS Command Injection via sel_EncrypTyp Parameter
Sep 12, 2025
CVSS 7.3
EPSS 0.01
CVE-2025-10322 MEDIUM
Wavlink WL-WN578W2 221110 - Weak Password Recovery Mechanism via sysinit.html newpass/confpass Parameters
Sep 12, 2025
CVSS 5.3
EPSS 0.00
CVE-2025-10321 MEDIUM
Wavlink WL-WN578W2 - Information Disclosure via /live_online.shtml
Sep 12, 2025
CVSS 5.3
EPSS 0.00
CVE-2025-50757 MEDIUM
Wavlink WN535K3 - Command Injection
Sep 02, 2025
CVSS 6.5
EPSS 0.05
CVE-2025-50755 MEDIUM
Wavlink WN535K3 - Command Injection
Sep 02, 2025
CVSS 6.5
EPSS 0.05
CVE-2025-9149 MEDIUM
Wavlink WL-NU516U1 M16U1_V240425 - Command Injection
Aug 19, 2025
CVSS 6.3
EPSS 0.01
CVE-2025-50756 CRITICAL
Wavlink WN535K3 - Command Injection
Jul 14, 2025
CVSS 9.8
EPSS 0.10
CVE-2025-5408 CRITICAL
WAVLINK QUANTUM D2G- V1410_240222 - Buffer Overflow
Jun 01, 2025
CVSS 9.8
EPSS 0.01
CVE-2025-44882 CRITICAL
Wavlink WL-WN579A3 v1.0 - OS Command Injection via firewall.cgi
May 20, 2025
CVSS 9.8
EPSS 0.14
CVE-2025-44880 CRITICAL
Wavlink WL-WN579A3 v1.0 - OS Command Injection via adm.cgi
May 20, 2025
CVSS 9.8
EPSS 0.14
CVE-2025-44881 CRITICAL
Wavlink WL-WN579A3 v1.0 - OS Command Injection via qos.cgi
May 20, 2025
CVSS 9.8
EPSS 0.14
CVE-2025-44868 CRITICAL
Wavlink WL-WN530H4 20220801 - OS Command Injection via pingIp Parameter
May 02, 2025
CVSS 9.8
EPSS 0.10
CVE-2025-25528 MEDIUM
Wavlink WL-WN575A3 RPT75A3.V4300 - Unauthenticated Buffer Overflow
Feb 11, 2025
CVSS 5.1
EPSS 0.03
CVE-2024-48705 MEDIUM
Wavlink AC1200 M32A3_V1410_230602 and M32A3_V1410_240222 - Authenticated Command Injection via newpass Field in adm.cgi
Sep 02, 2025
CVSS 6.5
EPSS 0.11
CVE-2024-39803 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Stack Overflow via qos.cgi sel_mode
Jan 14, 2025
CVSS 9.1
EPSS 0.01
CVE-2024-39802 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Stack Overflow via qos.cgi qos_dat
Jan 14, 2025
CVSS 9.1
EPSS 0.00
CVE-2024-39801 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Authenticated Stack-Based Buffer Overflow via qos_bandwidth POST Parameter
Jan 14, 2025
CVSS 9.1
EPSS 0.00
CVE-2024-39800 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - RCE
Jan 14, 2025
CVSS 9.1
EPSS 0.00
CVE-2024-39799 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - RCE
Jan 14, 2025
CVSS 9.1
EPSS 0.00
CVE-2024-39798 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - RCE
Jan 14, 2025
CVSS 9.1
EPSS 0.00
CVE-2024-39795 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Permission Bypass
Jan 14, 2025
CVSS 9.1
EPSS 0.00
CVE-2024-39794 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Auth Bypass
Jan 14, 2025
CVSS 9.1
EPSS 0.00
CVE-2024-39793 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Auth Bypass
Jan 14, 2025
CVSS 9.1
EPSS 0.00
CVE-2024-39790 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Auth Bypass
Jan 14, 2025
CVSS 9.1
EPSS 0.00