CVE-2020-13117
wavlink wn575a4_firmware Improper Neutralization of Special Elements used in a Command ('Command Injection')
Record summary
CVE-2020-13117 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
Wavlink WN575A4, WN579X3, and WN530G3A devices through 2020-05-15 allow unauthenticated remote users to inject commands via the key parameter in a login request.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Dec 11, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
wn575a4_firmwareBrowse wavlink / wn575a4_firmware | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICALWavlink Multiple AP - Remote Command InjectionCVSS 9.8
Wavlink products are affected by a vulnerability that may allow remote unauthenticated users to execute arbitrary commands as root on Wavlink devices. The user input is not properly sanitized which allows command injection via the "key" parameter in a login request. It has been tested on Wavlink WN575A4 and WN579X3 devices, but other products may also be affected.
Impact
Successful exploitation of this vulnerability could lead to unauthorized access, data leakage, and potential compromise of the affected device.
Remediation
Apply the latest firmware update provided by the vendor to mitigate this vulnerability.
Source: ProjectDiscovery