PT-2021-9562 · Wavlink · Wavlink Wn579X3+1

Jose Antonio Pérez Piedra

·

Published

2021-02-09

·

Updated

2025-08-19

·

CVE-2020-13117

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Wavlink WN575A4 and WN579X3 devices through 2020-05-15
Description The issue allows unauthenticated remote users to inject commands via the key parameter in a "login request" API endpoint.
Recommendations For Wavlink WN575A4 and WN579X3 devices through 2020-05-15, avoid using the key parameter in the affected login request until the issue is resolved. Restrict access to the login functionality to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2020-13117

Affected Products

Wavlink Wn575A4
Wavlink Wn579X3