WN551K1
by Wavlink
CVEs (6)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-10973 | Hig | 0.49 | 7.5 | 0.08 | May 7, 2020 | An issue was discovered in Wavlink WN530HG4, Wavlink WN531G3, Wavlink WN533A8, and Wavlink WN551K1 affecting /cgi-bin/ExportAllSettings.sh where a crafted POST request returns the current configuration of the device, including the administrator password. No authentication is… | ||
| CVE-2024-38892 | Med | 0.42 | 6.5 | 0.00 | Jun 24, 2024 | An issue in Wavlink WN551K1 allows a remote attacker to obtain sensitive information via the ExportAllSettings.sh component. | ||
| CVE-2024-38896 | Med | 0.35 | 5.3 | 0.01 | Jun 24, 2024 | WAVLINK WN551K1 found a command injection vulnerability through the start_hour parameter of /cgi-bin/nightled.cgi. | ||
| CVE-2024-38894 | Med | 0.35 | 5.3 | 0.01 | Jun 24, 2024 | WAVLINK WN551K1 found a command injection vulnerability through the IP parameter of /cgi-bin/touchlist_sync.cgi. | ||
| CVE-2024-38897 | Med | 0.34 | 5.3 | 0.00 | Jun 24, 2024 | WAVLINK WN551K1'live_check.shtml enables attackers to obtain sensitive router information. | ||
| CVE-2024-38895 | Med | 0.34 | 5.3 | 0.00 | Jun 24, 2024 | WAVLINK WN551K1'live_mfg.shtml enables attackers to obtain sensitive router information. |
- risk 0.49cvss 7.5epss 0.08
An issue was discovered in Wavlink WN530HG4, Wavlink WN531G3, Wavlink WN533A8, and Wavlink WN551K1 affecting /cgi-bin/ExportAllSettings.sh where a crafted POST request returns the current configuration of the device, including the administrator password. No authentication is…
- risk 0.42cvss 6.5epss 0.00
An issue in Wavlink WN551K1 allows a remote attacker to obtain sensitive information via the ExportAllSettings.sh component.
- risk 0.35cvss 5.3epss 0.01
WAVLINK WN551K1 found a command injection vulnerability through the start_hour parameter of /cgi-bin/nightled.cgi.
- risk 0.35cvss 5.3epss 0.01
WAVLINK WN551K1 found a command injection vulnerability through the IP parameter of /cgi-bin/touchlist_sync.cgi.
- risk 0.34cvss 5.3epss 0.00
WAVLINK WN551K1'live_check.shtml enables attackers to obtain sensitive router information.
- risk 0.34cvss 5.3epss 0.00
WAVLINK WN551K1'live_mfg.shtml enables attackers to obtain sensitive router information.