VYPR

Wavlink Sync Server Rce

by Camdsmith

CVEs (2)

  • CVE-2026-89010CriSep 11, 2026
    risk 0.64cvss 9.8epss

    WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted filenames to the sync_server daemon on TCP port 13136.…

  • CVE-2026-89009CriSep 11, 2026
    risk 0.59cvss 9.1epss

    WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated arbitrary file write vulnerability that allows remote attackers to overwrite any file on the device by sending a crafted payload to the sync_server daemon on TCP port 13136.…