CVE-2020-12124: OS Command Injection
A remote command-line injection vulnerability in the /cgi-bin/liveapi.cgi endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to execute arbitrary Linux commands as root without authentication.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-12124?
CVE-2020-12124 is a remote command-line injection vulnerability in the /cgi-bin/live_api.cgi endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 router.
What is the severity of CVE-2020-12124?
CVE-2020-12124 has a severity rating of 9.8 (Critical).
How does CVE-2020-12124 work?
CVE-2020-12124 allows an attacker to execute arbitrary Linux commands as root without authentication by exploiting a remote command-line injection vulnerability in the /cgi-bin/live_api.cgi endpoint of the WAVLINK WN530H4 router.
Is my WAVLINK WN530H4 router affected by CVE-2020-12124?
If you are using the WAVLINK WN530H4 M30H4.V5030.190403 firmware, your router is affected by CVE-2020-12124.
How can I fix CVE-2020-12124?
To fix CVE-2020-12124, it is recommended to update your WAVLINK WN530H4 router firmware to a version that has addressed the vulnerability.