CVE-2020-13117
Published Feb 9, 2021Wavlink WN575A4, WN579X3, and WN530G3A devices through 2020-05-15 allow unauthenticated remote users to inject commands via the key parameter in a login request.
Vendor/product archive
2 CVEs tagged to wavlink / wn575a4_firmware — 1 Critical, 1 High, 0 Medium, 0 Low, 0 Unrated.
Wavlink WN575A4, WN579X3, and WN530G3A devices through 2020-05-15 allow unauthenticated remote users to inject commands via the key parameter in a login request.
An issue was discovered affecting a backup feature where a crafted POST request returns the current configuration of the device in cleartext, including the administrator password.…