First published: Tue Feb 09 2021(Updated: )
Wavlink WN575A4 and WN579X3 devices through 2020-05-15 allow unauthenticated remote users to inject commands via the key parameter in a login request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Wavlink Wn575a4 Firmware | <=2020-05-15 | |
Wavlink WN575A4 | ||
Wavlink Wn579x3 Firmware | <=2020-05-15 | |
Wavlink WN579X3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-13117 is a vulnerability in Wavlink WN575A4 and WN579X3 devices that allows unauthenticated remote users to inject commands via the key parameter in a login request.
CVE-2020-13117 has a severity rating of 9.8 (critical).
Wavlink WN575A4 and WN579X3 devices with firmware up to and including 2020-05-15 are affected by CVE-2020-13117.
Unauthenticated remote users can exploit CVE-2020-13117 by injecting commands via the key parameter in a login request.
There is currently no known fix or patch for CVE-2020-13117. It is recommended to update to the latest firmware version if available and implement additional security measures.