CVE-2020-13117: Command Injection
Wavlink WN575A4 and WN579X3 devices through 2020-05-15 allow unauthenticated remote users to inject commands via the key parameter in a login request.
Other sources
Wavlink WN575A4, WN579X3, and WN530G3A devices through 2020-05-15 allow unauthenticated remote users to inject commands via the key parameter in a login request.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-13117?
CVE-2020-13117 is a vulnerability in Wavlink WN575A4 and WN579X3 devices that allows unauthenticated remote users to inject commands via the key parameter in a login request.
How severe is CVE-2020-13117?
CVE-2020-13117 has a severity rating of 9.8 (critical).
Which Wavlink devices are affected by CVE-2020-13117?
Wavlink WN575A4 and WN579X3 devices with firmware up to and including 2020-05-15 are affected by CVE-2020-13117.
How can unauthenticated remote users exploit CVE-2020-13117?
Unauthenticated remote users can exploit CVE-2020-13117 by injecting commands via the key parameter in a login request.
Is there a fix for CVE-2020-13117?
There is currently no known fix or patch for CVE-2020-13117. It is recommended to update to the latest firmware version if available and implement additional security measures.