PT-2021-9562 · Wavlink · Wavlink Wn579X3+1
Jose Antonio Pérez Piedra
·
Published
2021-02-09
·
Updated
2025-08-19
·
CVE-2020-13117
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Wavlink WN575A4 and WN579X3 devices through 2020-05-15
Description
The issue allows unauthenticated remote users to inject commands via the
key parameter in a "login request" API endpoint.Recommendations
For Wavlink WN575A4 and WN579X3 devices through 2020-05-15, avoid using the
key parameter in the affected login request until the issue is resolved. Restrict access to the login functionality to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wavlink Wn575A4
Wavlink Wn579X3