Wavlink · Wavlink Wl-Wn575A3 · CVE-2023-38861
**Name of the Vulnerable Software and Affected Versions**
Wavlink WL WNJ575A3 version R75A3 V1410 220513
**Description**
An issue in the software allows a remote attacker to execute arbitrary code via the `username` parameter of the `set sys adm` function in `adm.cgi`. This enables the attacker to gain unauthorized access and control over the system.
**Recommendations**
For version R75A3 V1410 220513, as a temporary workaround, consider disabling the `set sys adm` function in `adm.cgi` until a patch is available. Restrict access to the `adm.cgi` endpoint to minimize the risk of exploitation. Avoid using the `username` parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.