Home/Product/wavlink wn535g3 firmware
Product

wavlink wn535g3 firmware

23 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2022-35538
all versions
WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 wireless.cgi has no filtering on parameters: delete_list, delete_al_mac, b_de
9.8CRITICAL
CVE-2022-35537
all versions
WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 wireless.cgi has no filtering on parameters: mac_5g and Newname, which leads
9.8CRITICAL
CVE-2022-35536
all versions
WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 qos.cgi has no filtering on parameters: qos_bandwith and qos_dat, which leads
9.8CRITICAL
CVE-2022-35535
all versions
WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 wireless.cgi has no filtering on parameter macAddr, which leads to command in
9.8CRITICAL
CVE-2022-35534
all versions
WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 wireless.cgi has no filtering on parameter hiddenSSID32g and SSID2G2, which l
9.8CRITICAL
CVE-2022-35533
all versions
WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 qos.cgi has no filtering on parameters: cli_list and cli_num, which leads to
9.8CRITICAL
CVE-2022-35526
all versions
WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 login.cgi has no filtering on parameter key, which leads to command injection
9.8CRITICAL
CVE-2022-35525
all versions
WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 adm.cgi has no filtering on parameter led_switch, which leads to command inje
9.8CRITICAL
CVE-2022-35524
all versions
WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 adm.cgi has no filtering on parameters: wlan_signal, web_pskValue, sel_Encryp
9.8CRITICAL
CVE-2022-35523
all versions
WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 firewall.cgi has no filtering on parameter del_mac and parameter flag, which
9.8CRITICAL
CVE-2022-35522
all versions
WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 adm.cgi has no filtering on parameters: ppp_username, ppp_passwd, rwan_gatewa
9.8CRITICAL
CVE-2022-35521
all versions
WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 firewall.cgi has no filtering on parameters: remoteManagementEnabled, blockPo
9.8CRITICAL
CVE-2022-35520
all versions
WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 api.cgi has no filtering on parameter ufconf, and this is a hidden parameter
9.8CRITICAL
CVE-2022-35519
all versions
WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 firewall.cgi has no filtering on parameter add_mac, which leads to command in
9.8CRITICAL
CVE-2022-35518
all versions
WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 nas.cgi has no filtering on parameters: User1Passwd and User1, which leads to
9.8CRITICAL
CVE-2022-35517
all versions
WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 adm.cgi has no filtering on parameters: web_pskValue, wl_Method, wlan_ssid, E
8.8HIGH
CVE-2022-34577
all versions
A vulnerability in adm.cgi of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to execute arbitrary code via a crafted POST r
9.8CRITICAL
CVE-2022-34576
all versions
A vulnerability in /cgi-bin/ExportAllSettings.sh of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to execute arbitrary cod
7.5HIGH
CVE-2022-31846
all versions
A vulnerability in live_mfg.shtml of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to obtain sensitive router information
7.5HIGH
CVE-2022-31845
all versions
A vulnerability in live_check.shtml of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to obtain sensitive router informatio
7.5HIGH
CVE-2022-30489
all versions
WAVLINK WN535 G3 was discovered to contain a cross-site scripting (XSS) vulnerability via the hostname parameter at /cgi-bin/login
6.1MEDIUM
CVE-2020-10974
all versions
An issue was discovered affecting a backup feature where a crafted POST request returns the current configuration of the device in
7.5HIGH
CVE-2020-12266
all versions
An issue was discovered where there are multiple externally accessible pages that do not require any sort of authentication, and s
7.5HIGH
threatengine.sh