VYPR

Wl Wn530hg4 Firmware

by Wavlink

CVEs (6)

  • CVE-2020-15490CriJul 1, 2020
    risk 0.64cvss 9.8epss 0.04

    An issue was discovered on Wavlink WL-WN530HG4 M30HG4.V5030.191116 devices. Multiple buffer overflow vulnerabilities exist in CGI scripts, leading to remote code execution with root privileges. (The set of affected scripts is similar to CVE-2020-12266.)

  • CVE-2020-15489CriJul 1, 2020
    risk 0.64cvss 9.8epss 0.04

    An issue was discovered on Wavlink WL-WN530HG4 M30HG4.V5030.191116 devices. Multiple shell metacharacter injection vulnerabilities exist in CGI scripts, leading to remote code execution with root privileges.

  • CVE-2022-34047HigJul 20, 2022
    risk 0.53cvss 7.5epss 0.21

    An access control issue in Wavlink WN530HG4 M30HG4.V5030.191116 allows attackers to obtain usernames and passwords via view-source:http://IP_ADDRESS/set_safety.shtml?r=52300 and searching for [var syspasswd].

  • CVE-2022-48166HigFeb 6, 2023
    risk 0.49cvss 7.5epss 0.03

    An access control issue in Wavlink WL-WN530HG4 M30HG4.V5030.201217 allows unauthenticated attackers to download configuration data and log files and obtain admin credentials.

  • CVE-2020-12266HigApr 27, 2020
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered where there are multiple externally accessible pages that do not require any sort of authentication, and store system information for internal usage. The devices automatically query these pages to update dashboards and other statistics, but the pages can…

  • CVE-2022-34049MedJul 20, 2022
    risk 0.35cvss 5.3epss 0.03

    An access control issue in Wavlink WN530HG4 M30HG4.V5030.191116 allows unauthenticated attackers to download log files and configuration data.