VYPR

Wn551k1 Firmware

by Wavlink

CVEs (7)

  • CVE-2020-10973HigMay 7, 2020
    risk 0.49cvss 7.5epss 0.08

    An issue was discovered in Wavlink WN530HG4, Wavlink WN531G3, Wavlink WN533A8, and Wavlink WN551K1 affecting /cgi-bin/ExportAllSettings.sh where a crafted POST request returns the current configuration of the device, including the administrator password. No authentication is…

  • CVE-2020-12266HigApr 27, 2020
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered where there are multiple externally accessible pages that do not require any sort of authentication, and store system information for internal usage. The devices automatically query these pages to update dashboards and other statistics, but the pages can…

  • CVE-2024-38892MedJun 24, 2024
    risk 0.42cvss 6.5epss 0.00

    An issue in Wavlink WN551K1 allows a remote attacker to obtain sensitive information via the ExportAllSettings.sh component.

  • CVE-2024-38896MedJun 24, 2024
    risk 0.35cvss 5.3epss 0.01

    WAVLINK WN551K1 found a command injection vulnerability through the start_hour parameter of /cgi-bin/nightled.cgi.

  • CVE-2024-38894MedJun 24, 2024
    risk 0.35cvss 5.3epss 0.01

    WAVLINK WN551K1 found a command injection vulnerability through the IP parameter of /cgi-bin/touchlist_sync.cgi.

  • CVE-2024-38897MedJun 24, 2024
    risk 0.34cvss 5.3epss 0.00

    WAVLINK WN551K1'live_check.shtml enables attackers to obtain sensitive router information.

  • CVE-2024-38895MedJun 24, 2024
    risk 0.34cvss 5.3epss 0.00

    WAVLINK WN551K1'live_mfg.shtml enables attackers to obtain sensitive router information.