PT-2025-35572 · Wavlink · Wavlink Ac1200

Published

2025-09-02

·

Updated

2025-09-03

·

CVE-2024-48705

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Wavlink AC1200 versions M32A3 V1410 230602 and M32A3 V1410 240222
Description The Wavlink AC1200 is susceptible to a post-authentication command injection when resetting the password. The issue resides within the adm.cgi binary, specifically in the set sys adm function, due to insufficient sanitization of the newpass field provided by the user.
Recommendations Wavlink AC1200 version M32A3 V1410 230602: Update to a newer firmware version. Wavlink AC1200 version M32A3 V1410 240222: Update to a newer firmware version.

Exploit

Fix

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2024-48705

Affected Products

Wavlink Ac1200