VYPR
Vendor

WAYOS

Products
4
CVEs
2
Across products
4
Status
Private

Products

4

Recent CVEs

2
  • CVE-2025-11045HigSep 26, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was identified in WAYOS LQ_04, LQ_05, LQ_06, LQ_07 and LQ_09 22.03.17. This affects an unknown function of the file /usb_paswd.asp. The manipulation of the argument Name leads to command injection. The attack can be initiated remotely. The exploit is publicly available and might be used.

  • CVE-2026-2548MedFeb 16, 2026
    risk 0.41cvss 6.3epss 0.02

    A flaw has been found in WAYOS FBM-220G 24.10.19. This affects the function sub_40F820 of the file rc. Executing a manipulation of the argument upnp_waniface/upnp_ssdp_interval/upnp_max_age can lead to command injection. The attack can be executed remotely. The vendor was contacted early about this disclosure but did not respond in any way.