CVE-2025-50756: Command Injection
Wavlink WN535K3 20191010 was found to contain a command injection vulnerability in the setsysadm function via the newpass parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-50756?
CVE-2025-50756 is considered a critical severity vulnerability due to its potential for command injection.
How do I fix CVE-2025-50756?
To fix CVE-2025-50756, update the Wavlink WN535K3 device firmware to the latest version that addresses this vulnerability.
What is the impact of exploiting CVE-2025-50756?
Exploitation of CVE-2025-50756 allows attackers to execute arbitrary commands on the affected Wavlink WN535K3 device.
Which devices are affected by CVE-2025-50756?
CVE-2025-50756 affects the Wavlink WN535K3 router specifically identified by the version from October 2019.
Is CVE-2025-50756 being actively exploited?
There are indications that CVE-2025-50756 may be actively exploited in the wild, making it essential to apply mitigations immediately.