CVE-2020-12125
Description
A remote buffer overflow vulnerability in the /cgi-bin/makeRequest.cgi endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to execute arbitrary machine instructions as root without authentication.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A pre-authenticated remote buffer overflow in the /cgi-bin/makeRequest.cgi endpoint of the WAVLINK WN530H4 router allows root-level arbitrary code execution.
Vulnerability
The WAVLINK WN530H4 router, running firmware version M30H4.V5030.190403, contains a remote buffer overflow vulnerability in the /cgi-bin/makeRequest.cgi CGI endpoint. The endpoint does not properly sanitize user-supplied input before copying it into a fixed-size buffer, allowing an attacker to overflow the buffer and overwrite adjacent memory. The vulnerability is reachable without any authentication or prior access to the device [1].
Exploitation
An attacker can send a crafted HTTP POST request to the /cgi-bin/makeRequest.cgi endpoint with an overly long parameter value. No authentication is required, and the attacker only needs network connectivity to the router's administrative web interface (typically on port 80). The exploit triggers the buffer overflow, injecting arbitrary machine instructions that will be executed in the context of the root user.
Impact
Successful exploitation allows an unauthenticated, remote attacker to execute arbitrary machine instructions as the root user on the device. This results in full compromise of the router, including the ability to read sensitive data, modify configuration, install persistent malware, or use the device as a foothold for further network attacks.
Mitigation
As of the publication date (2020-10-02), no firmware update or patch has been released by WAVLINK to address this vulnerability. Users are advised to replace the device if it is no longer supported, restrict access to the management interface to trusted networks only, and monitor for malicious traffic targeting the /cgi-bin/makeRequest.cgi endpoint [1].
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- WAVLINK/WN530H4description
- Range: = M30H4.V5030.190403
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- cerne.xyz/bugs/CVE-2020-12125mitrex_refsource_MISC
- www.wavlink.com/en_us/product/WL-WN530H4.htmlmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.