Show filters
138 Total Results
Displaying 121-130 of 138
Sort by:
Attacker Value
Unknown

CVE-2022-31309

Disclosure Date: June 14, 2022 (last updated February 23, 2025)
A vulnerability in live_check.shtml of WAVLINK AERIAL X 1200M M79X3.V5030.180719 allows attackers to obtain sensitive router information via execution of the exec cmd function.
Attacker Value
Unknown

CVE-2022-31308

Disclosure Date: June 14, 2022 (last updated February 23, 2025)
A vulnerability in live_mfg.shtml of WAVLINK AERIAL X 1200M M79X3.V5030.191012 allows attackers to obtain sensitive router information via execution of the exec cmd function.
Attacker Value
Unknown

CVE-2022-30489

Disclosure Date: May 13, 2022 (last updated February 23, 2025)
WAVLINK WN535 G3 was discovered to contain a cross-site scripting (XSS) vulnerability via the hostname parameter at /cgi-bin/login.cgi.
Attacker Value
Unknown

CVE-2022-23900

Disclosure Date: April 07, 2022 (last updated February 23, 2025)
A command injection vulnerability in the API of the Wavlink WL-WN531P3 router, version M31G3.V5030.201204, allows an attacker to achieve unauthorized remote code execution via a malicious POST request through /cgi-bin/adm.cgi.
Attacker Value
Unknown

CVE-2021-44260

Disclosure Date: March 17, 2022 (last updated February 23, 2025)
A vulnerability is in the 'live_mfg.html' page of the WAVLINK AC1200, version WAVLINK-A42W-1.27.6-20180418, which can allow a remote attacker to access this page without any authentication. When processed, it exposes some key information of the manager of router.
Attacker Value
Unknown

CVE-2021-44259

Disclosure Date: March 17, 2022 (last updated February 23, 2025)
A vulnerability is in the 'wx.html' page of the WAVLINK AC1200, version WAVLINK-A42W-1.27.6-20180418, which can allow a remote attacker to access this page without any authentication. When an unauthorized user accesses this page directly, it connects to this device as a friend of the device owner.
Attacker Value
Unknown

CVE-2020-13117

Disclosure Date: February 09, 2021 (last updated February 22, 2025)
Wavlink WN575A4 and WN579X3 devices through 2020-05-15 allow unauthenticated remote users to inject commands via the key parameter in a login request.
Attacker Value
Unknown

CVE-2020-12126

Disclosure Date: October 02, 2020 (last updated February 22, 2025)
Multiple authentication bypass vulnerabilities in the /cgi-bin/ endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allow an attacker to leak router settings, change configuration variables, and cause denial of service via an unauthenticated endpoint.
Attacker Value
Unknown

CVE-2020-12123

Disclosure Date: October 02, 2020 (last updated February 22, 2025)
CSRF vulnerabilities in the /cgi-bin/ directory of the WAVLINK WN530H4 M30H4.V5030.190403 allow an attacker to remotely access router endpoints, because these endpoints do not contain CSRF tokens. If a user is authenticated in the router portal, then this attack will work.
Attacker Value
Unknown

CVE-2020-12127

Disclosure Date: October 02, 2020 (last updated February 22, 2025)
An information disclosure vulnerability in the /cgi-bin/ExportAllSettings.sh endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to leak router settings, including cleartext login details, DNS settings, and other sensitive information without authentication.