CVE-2026-89009: WAVLINK WN535M1/WN535M3 Unauthenticated Arbitrary File Write via sync_server
WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1V250922 contain an unauthenticated arbitrary file write vulnerability that allows remote attackers to overwrite any file on the device by sending a crafted payload to the syncserver daemon on TCP port 13136. The daemon, which runs as root and requires no authentication, accepts a 100-byte filename field in its protocol header without path canonicalization, allowing attackers to supply an absolute path and write arbitrary content to overwrite startup scripts or credential stores to achieve persistent system compromise.
Affected Software
Event History
Frequently Asked Questions
Which devices and firmware are affected?
WAVLINK WN535M1 and WN535M3 routers running firmware earlier than M35M1_V250922 are affected.
Does exploitation require credentials or user interaction?
No. The sync_server daemon accepts connections without authentication, so a remote attacker can exploit the issue without credentials or user interaction.
What network exposure is required for exploitation?
The attacker must be able to reach the sync_server daemon on TCP port 13136. Devices with that port reachable from an untrusted network are exposed to remote exploitation.
What is the likely impact of a successful attack?
An attacker can overwrite arbitrary files as root, including startup scripts or credential stores. This can enable persistent compromise of the router and affect its integrity and availability.
How can administrators determine whether a device is vulnerable?
Identify whether the device is a WN535M1 or WN535M3 and check whether its firmware version is earlier than M35M1_V250922. Also determine whether TCP port 13136 exposes the unauthenticated sync_server daemon to untrusted networks.