VYPR

Vendor CVEs

Wavlink

All CVEs

221 total · sorted by risk
  • CVE-2024-38896MedJun 24, 2024
    risk 0.35cvss 5.3epss 0.01

    WAVLINK WN551K1 found a command injection vulnerability through the start_hour parameter of /cgi-bin/nightled.cgi.

  • CVE-2024-38894MedJun 24, 2024
    risk 0.35cvss 5.3epss 0.01

    WAVLINK WN551K1 found a command injection vulnerability through the IP parameter of /cgi-bin/touchlist_sync.cgi.

  • CVE-2022-34049MedJul 20, 2022
    risk 0.35cvss 5.3epss 0.03

    An access control issue in Wavlink WN530HG4 M30HG4.V5030.191116 allows unauthenticated attackers to download log files and configuration data.

  • CVE-2025-10322MedSep 12, 2025
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been found in Wavlink WL-WN578W2 221110. The affected element is an unknown function of the file /sysinit.html. The manipulation of the argument newpass/confpass leads to weak password recovery. The attack is possible to be carried out remotely. The exploit…

  • CVE-2025-10321MedSep 12, 2025
    risk 0.34cvss 5.3epss 0.01

    A flaw has been found in Wavlink WL-WN578W2 221110. Impacted is an unknown function of the file /live_online.shtml. Executing manipulation can lead to information disclosure. The attack can be executed remotely. The exploit has been published and may be used. The vendor was…

  • CVE-2024-38897MedJun 24, 2024
    risk 0.34cvss 5.3epss 0.00

    WAVLINK WN551K1'live_check.shtml enables attackers to obtain sensitive router information.

  • CVE-2024-38895MedJun 24, 2024
    risk 0.34cvss 5.3epss 0.00

    WAVLINK WN551K1'live_mfg.shtml enables attackers to obtain sensitive router information.

  • CVE-2025-25528MedFeb 11, 2025
    risk 0.33cvss 5.1epss 0.04

    Multiple buffer overflow vulnerabilities in Wavlink WL-WN575A3 RPT75A3.V4300, which are caused by not performing strict length checks on user-controlled data. By successfully exploiting the vulnerabilities, attackers can crash the remote devices or execute arbitrary commands…

  • CVE-2026-3662MedMar 7, 2026
    risk 0.32cvss 4.7epss 0.18

    A vulnerability has been found in Wavlink WL-NU516U1 240425. This vulnerability affects the function usb_p910 of the file /cgi-bin/adm.cgi. Such manipulation of the argument Pr_mode leads to command injection. It is possible to launch the attack remotely. The exploit has been…

  • CVE-2026-3661MedMar 7, 2026
    risk 0.32cvss 4.7epss 0.17

    A flaw has been found in Wavlink WL-NU516U1 240425. This affects the function ota_new_upgrade of the file /cgi-bin/adm.cgi. This manipulation of the argument model causes command injection. It is possible to initiate the attack remotely. The exploit has been published and may be…

  • CVE-2025-10775MedSep 22, 2025
    risk 0.32cvss 4.7epss 0.20

    A security vulnerability has been detected in Wavlink WL-NU516U1 240425. This vulnerability affects the function sub_4012A0 of the file /cgi-bin/login.cgi. Such manipulation of the argument ipaddr leads to os command injection. It is possible to launch the attack remotely. The…

  • CVE-2024-10193MedOct 20, 2024
    risk 0.32cvss 4.7epss 0.15

    A vulnerability was found in WAVLINK WN530H4, WN530HG4 and WN572HG3 up to 20221028 and classified as critical. This issue affects the function ping_ddns of the file internet.cgi. The manipulation of the argument DDNS leads to command injection. The attack may be initiated…

  • CVE-2026-3704MedMar 8, 2026
    risk 0.31cvss 4.7epss 0.05

    A vulnerability has been found in Wavlink NU516U1 251208. This vulnerability affects the function sub_405B2C of the file /cgi-bin/firewall.cgi of the component Incomplete Fix CVE-2025-10959. The manipulation leads to command injection. It is possible to initiate the attack…

  • CVE-2023-3380MedJun 23, 2023
    risk 0.31cvss 4.7epss 0.04

    A vulnerability classified as critical has been found in Wavlink WN579X3 up to 20230615. Affected is an unknown function of the file /cgi-bin/adm.cgi of the component Ping Test. The manipulation of the argument pingIp leads to injection. It is possible to launch the attack…

  • CVE-2026-6559MedApr 19, 2026
    risk 0.28cvss 4.3epss 0.00

    A weakness has been identified in Wavlink WL-WN579A3 220323. This affects the function sub_401F80 of the file /cgi-bin/login.cgi. This manipulation of the argument Hostname causes cross site scripting. Remote exploitation of the attack is possible. Upgrading the affected…

  • CVE-2026-4166LowMar 16, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in Wavlink WL-NU516U1 240425. The impacted element is the function sub_404F68 of the file /cgi-bin/login.cgi. The manipulation of the argument homepage/hostname results in cross site scripting. The attack can be launched remotely. The exploit has been…

  • CVE-2026-4544LowMar 22, 2026
    risk 0.16cvss 2.4epss 0.00

    A vulnerability was determined in Wavlink WL-WN578W2 221110. This affects an unknown function of the file /cgi-bin/login.cgi of the component POST Request Handler. Executing a manipulation of the argument homepage/hostname/login_page can lead to cross site scripting. It is…

  • CVE-2026-3716LowMar 8, 2026
    risk 0.16cvss 2.4epss 0.00

    A vulnerability was determined in Wavlink WL-WN579X3-C 231124. This vulnerability affects the function sub_401AD4 of the file /cgi-bin/adm.cgi. Executing a manipulation of the argument Hostname can lead to cross site scripting. It is possible to launch the attack remotely. The…

  • CVE-2026-15513MedJul 13, 2026
    risk 0.00cvss 6.3epss 0.01

    A security flaw has been discovered in Wavlink WL-NU516U1 260515. This affects the function wlink_uci_set_value of the file /cgi-bin/adm.cgi. Performing a manipulation of the argument lan_ip results in os command injection. The attack can be initiated remotely. The exploit has…

  • CVE-2026-13539HigJun 29, 2026
    risk 0.00cvss 8.8epss 0.00

    A vulnerability was identified in Wavlink WL-NU516U1-A M16U1_V240425. The impacted element is the function sub_407504 of the file /cgi-bin/wireless.cgi of the component POST Parameter Handler. Such manipulation of the argument Guest_ssid leads to stack-based buffer overflow. The…

  • CVE-2026-13538MedJun 29, 2026
    risk 0.00cvss 6.3epss 0.01

    A vulnerability was determined in Wavlink WL-NU516U1-A M16U1_V240425. The affected element is the function sub_401D68 of the file /cgi-bin/wireless.cgi of the component POST Parameter Handler. This manipulation of the argument SSID2G2/SSID5G2/AuthMethod2/WPAPSK12 causes command…

Page 5 of 5