Show filters
138 Total Results
Displaying 71-80 of 138
Sort by:
Attacker Value
Unknown

CVE-2023-32620

Disclosure Date: June 30, 2023 (last updated October 08, 2023)
Improper authentication vulnerability in WL-WN531AX2 firmware versions prior to 2023526 allows a network-adjacent attacker to obtain a password for the wireless network.
Attacker Value
Unknown

CVE-2023-32613

Disclosure Date: June 30, 2023 (last updated October 08, 2023)
Exposure of resource to wrong sphere issue exists in WL-WN531AX2 firmware versions prior to 2023526, which may allow a network-adjacent attacker to use functions originally available after login without logging in.
Attacker Value
Unknown

CVE-2023-32612

Disclosure Date: June 30, 2023 (last updated October 08, 2023)
Client-side enforcement of server-side security issue exists in WL-WN531AX2 firmware versions prior to 2023526, which may allow an attacker with an administrative privilege to execute OS commands with the root privilege.
Attacker Value
Unknown

CVE-2023-3380

Disclosure Date: June 23, 2023 (last updated October 08, 2023)
A vulnerability classified as critical has been found in Wavlink WN579X3 up to 20230615. Affected is an unknown function of the file /cgi-bin/adm.cgi of the component Ping Test. The manipulation of the argument pingIp leads to injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-232236. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Attacker Value
Unknown

CVE-2023-29708

Disclosure Date: June 22, 2023 (last updated October 08, 2023)
An issue was discovered in /cgi-bin/adm.cgi in WavLink WavRouter version RPT70HA1.x, allows attackers to force a factory reset via crafted payload.
Attacker Value
Unknown

CVE-2022-48166

Disclosure Date: February 06, 2023 (last updated October 08, 2023)
An access control issue in Wavlink WL-WN530HG4 M30HG4.V5030.201217 allows unauthenticated attackers to download configuration data and log files and obtain admin credentials.
Attacker Value
Unknown

CVE-2022-48164

Disclosure Date: February 06, 2023 (last updated October 08, 2023)
An access control issue in the component /cgi-bin/ExportLogs.sh of Wavlink WL-WN533A8 M33A8.V5030.190716 allows unauthenticated attackers to download configuration data and log files and obtain admin credentials.
Attacker Value
Unknown

CVE-2022-48165

Disclosure Date: February 03, 2023 (last updated October 08, 2023)
An access control issue in the component /cgi-bin/ExportLogs.sh of Wavlink WL-WN530H4 M30H4.V5030.210121 allows unauthenticated attackers to download configuration data and log files and obtain admin credentials.
Attacker Value
Unknown

CVE-2022-44356

Disclosure Date: November 29, 2022 (last updated October 08, 2023)
WAVLINK Quantum D4G (WL-WN531G3) running firmware versions M31G3.V5030.201204 and M31G3.V5030.200325 has an access control issue which allows unauthenticated attackers to download configuration data and log files.
Attacker Value
Unknown

CVE-2022-37149

Disclosure Date: August 30, 2022 (last updated October 08, 2023)
WAVLINK WL-WN575A3 RPT75A3.V4300.201217 was discovered to contain a command injection vulnerability when operating the file adm.cgi. This vulnerability allows attackers to execute arbitrary commands via the username parameter.