PT-2025-39670 · Wavlink · Wavlink M86X3A V240730

Meigui637

·

Published

2025-06-25

·

Updated

2025-09-26

·

CVE-2025-55847

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Wavlink M86X3A V240730 (affected versions not specified)
Description The software contains a buffer overflow issue in the /cgi-bin/ExportAllSettings.cgi file. The problem is due to insufficient validation of the length of input data received through the Cookie parameter. Successful exploitation could allow attackers to execute arbitrary code or cause a denial of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Resource Exhaustion

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2026-00815
CVE-2025-55847

Affected Products

Wavlink M86X3A V240730