CVE-2020-12123
Description
CSRF vulnerabilities in the /cgi-bin/ directory of the WAVLINK WN530H4 M30H4.V5030.190403 allow an attacker to remotely access router endpoints, because these endpoints do not contain CSRF tokens. If a user is authenticated in the router portal, then this attack will work.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
CSRF in WAVLINK WN530H4 router allows authenticated attackers to execute actions via /cgi-bin endpoints without CSRF tokens.
Vulnerability
The WAVLINK WN530H4 router running firmware version M30H4.V5030.190403 does not implement CSRF tokens on endpoints under the /cgi-bin/ directory. This CSRF vulnerability allows an attacker to trigger actions on the router if an authenticated user visits a malicious page.
Exploitation
An attacker can craft a malicious website or email that, when visited by an authenticated router user, sends requests to the router's /cgi-bin/ endpoints. Since the endpoints lack CSRF protection, the attacker's requests are executed as if they came from the legitimate user. No additional authentication or user interaction beyond visiting the malicious page is required.
Impact
Successful exploitation allows the attacker to remotely access router endpoints with the privileges of the authenticated user. This could lead to unauthorized changes to router settings, including configuration modifications, or other actions permitted by the router's admin interface.
Mitigation
As of the publication date (2020-10-02), no firmware update is mentioned in available references. Users should consider workarounds such as disabling remote management or using a VPN to protect the router's management interface. The vendor's product page [1] does not provide security patches.
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- WAVLINK/WN530H4description
- Range: = M30H4.V5030.190403
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- cerne.xyz/bugs/CVE-2020-12123mitrex_refsource_MISC
- www.wavlink.com/en_us/product/WL-WN530H4.htmlmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.