CVE-2020-12126: Critical severity wavlink wl-wn530h4 firmware vulnerability
Multiple authentication bypass vulnerabilities in the /cgi-bin/ endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allow an attacker to leak router settings, change configuration variables, and cause denial of service via an unauthenticated endpoint.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-12126?
CVE-2020-12126 is a vulnerability in the /cgi-bin/ endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 that allows an attacker to bypass authentication and gain unauthorized access.
How severe is CVE-2020-12126?
CVE-2020-12126 has a severity rating of 9.8 out of 10, making it a critical vulnerability.
What is the affected software/version for CVE-2020-12126?
The affected software/version for CVE-2020-12126 is the Wavlink WN530H4 M30H4.V5030.190403.
How can an attacker exploit CVE-2020-12126?
An attacker can exploit CVE-2020-12126 by bypassing authentication in the /cgi-bin/ endpoint and gain unauthorized access to leak router settings, change configuration variables, and cause denial of service.
Are all Wavlink WN530H4 routers affected by CVE-2020-12126?
No, only the Wavlink WN530H4 M30H4.V5030.190403 firmware version is affected by CVE-2020-12126.