CVE-2020-15489: OS Command Injection
An issue was discovered on Wavlink WL-WN530HG4 M30HG4.V5030.191116 devices. Multiple shell metacharacter injection vulnerabilities exist in CGI scripts, leading to remote code execution with root privileges.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-15489?
CVE-2020-15489 is a vulnerability discovered on Wavlink WL-WN530HG4 M30HG4.V5030.191116 devices that allows for remote code execution with root privileges.
How severe is CVE-2020-15489?
CVE-2020-15489 has a severity score of 9.8 out of 10, indicating a critical vulnerability.
How can I fix CVE-2020-15489?
There is no fix available for CVE-2020-15489 at the moment, but it is recommended to update to the latest firmware version once a patch is released by Wavlink.
What is the affected software for CVE-2020-15489?
The affected software for CVE-2020-15489 is Wavlink WL-WN530HG4 M30HG4.V5030.191116 firmware.
What is the Common Weakness Enumeration (CWE) ID for CVE-2020-15489?
The CWE ID for CVE-2020-15489 is CWE-78, which stands for Improper Neutralization of Special Elements used in an OS Command.