First published: Tue Feb 09 2021(Updated: )
Wavlink WN575A4 and WN579X3 devices through 2020-05-15 allow unauthenticated remote users to inject commands via the key parameter in a login request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Wavlink WN575A4 Firmware | <=2020-05-15 | |
Wavlink WN575A4 Firmware | ||
Wavlink Aerial X 1200m Firmware | <=2020-05-15 | |
Wavlink WL-WN579X3 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-13117 is a vulnerability in Wavlink WN575A4 and WN579X3 devices that allows unauthenticated remote users to inject commands via the key parameter in a login request.
CVE-2020-13117 has a severity rating of 9.8 (critical).
Wavlink WN575A4 and WN579X3 devices with firmware up to and including 2020-05-15 are affected by CVE-2020-13117.
Unauthenticated remote users can exploit CVE-2020-13117 by injecting commands via the key parameter in a login request.
There is currently no known fix or patch for CVE-2020-13117. It is recommended to update to the latest firmware version if available and implement additional security measures.