CVE-2023-32612

HIGH

WL-WN531AX2 <2023526 - Command Injection

Title source: llm
STIX 2.1

Description

Client-side enforcement of server-side security issue exists in WL-WN531AX2 firmware versions prior to 2023526, which may allow an attacker with an administrative privilege to execute OS commands with the root privilege.

Scores

CVSS v3 7.2
EPSS 0.0010
EPSS Percentile 26.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-565
Status published
Products (1)
wavlink/wl-wn531ax2_firmware < 2023526
Published Jun 30, 2023
Tracked Since Feb 18, 2026