CVE-2026-89009: WAVLINK WN535M1/WN535M3 Unauthenticated Arbitrary File Write via sync_server

Published Sep 11, 2026
·
Updated

WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1V250922 contain an unauthenticated arbitrary file write vulnerability that allows remote attackers to overwrite any file on the device by sending a crafted payload to the syncserver daemon on TCP port 13136. The daemon, which runs as root and requires no authentication, accepts a 100-byte filename field in its protocol header without path canonicalization, allowing attackers to supply an absolute path and write arbitrary content to overwrite startup scripts or credential stores to achieve persistent system compromise.

Affected Software

2 affected components
Wavlink WN535M1<M35M1_V250922
Wavlink WN535M3<M35M1_V250922

Event History

Sep 11, 2026
CVE Published
via MITRE·02:56 PM
Data Sourced
via MITRE·02:56 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which devices and firmware are affected?

WAVLINK WN535M1 and WN535M3 routers running firmware earlier than M35M1_V250922 are affected.

2

Does exploitation require credentials or user interaction?

No. The sync_server daemon accepts connections without authentication, so a remote attacker can exploit the issue without credentials or user interaction.

3

What network exposure is required for exploitation?

The attacker must be able to reach the sync_server daemon on TCP port 13136. Devices with that port reachable from an untrusted network are exposed to remote exploitation.

4

What is the likely impact of a successful attack?

An attacker can overwrite arbitrary files as root, including startup scripts or credential stores. This can enable persistent compromise of the router and affect its integrity and availability.

5

How can administrators determine whether a device is vulnerable?

Identify whether the device is a WN535M1 or WN535M3 and check whether its firmware version is earlier than M35M1_V250922. Also determine whether TCP port 13136 exposes the unauthenticated sync_server daemon to untrusted networks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203