VYPR

WN535M1

by Wavlink

CVEs (3)

  • CVE-2026-74843CriAug 17, 2026
    risk 0.65cvss 10.0epss 0.01

    A vulnerability was determined in Wavlink WN531P3 and WN535M1 V250922. Affected by this vulnerability is the function strcpy of the file /etc/lighttpd/www/cgi-bin/export_pingortrace.cgi of the component Export Pingortrace CGI. Executing a manipulation of the argument HTTP_COOKIE…

  • CVE-2026-89010CriSep 11, 2026
    risk 0.64cvss 9.8epss 0.03

    WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted filenames to the sync_server daemon on TCP port 13136.…

  • CVE-2026-89009CriSep 11, 2026
    risk 0.59cvss 9.1epss 0.01

    WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated arbitrary file write vulnerability that allows remote attackers to overwrite any file on the device by sending a crafted payload to the sync_server daemon on TCP port 13136.…