Vulnerabilidades en Wavlink

137 resultados
Análisis Vexday

O ecossistema de vulnerabilidades da Wavlink apresenta um volume expressivo de CVEs catalogadas, com 64 classificadas como críticas — número que demanda atenção redobrada de equipes de segurança que operam dispositivos desta fabricante. Embora nenhuma CVE conste atualmente no catálogo KEV da CISA, posicionando a taxa de exploração ativa abaixo da média geral, a presença de 16 falhas com prova de conceito pública eleva o risco de escalada, especialmente considerando que 14 vulnerabilidades surgiram nos últimos 90 dias, indicando superfície de ataque em expansão recente. A falha mais preocupante no momento é CVE-2024-39363, associada a CWE-77 (injeção de comandos), com score EPSS de 0,4809 — o mais alto observado no portfólio —, sugerindo probabilidade não desprezível de exploração ativa em horizonte próximo. Organizações que utilizam equipamentos Wavlink devem priorizar a aplicação de correções, monitorar ativamente CVEs com PoC disponível e tratar CWE-77 como vetor de risco estrutural neste ambiente.

CVE-2024-39754CRITICALA static login vulnerability exists in the wctrls functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted set of network pacEPSS 1.3%CVE-2024-39799CRITICALMultiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup() functionality of Wavlink AC3000 M33A8.V503EPSS 1.3%CVE-2024-39768CRITICALMultiple buffer overflow vulnerabilities exist in the internet.cgi set_qos() functionality of Wavlink AC3000 M33A8.V5030.210505. A speciallyEPSS 1.3%CVE-2024-39803CRITICALMultiple buffer overflow vulnerabilities exist in the qos.cgi qos_settings() functionality of Wavlink AC3000 M33A8.V5030.210505. A speciallyEPSS 1.3%CVE-2024-39770CRITICALMultiple buffer overflow vulnerabilities exist in the internet.cgi set_qos() functionality of Wavlink AC3000 M33A8.V5030.210505. A speciallyEPSS 1.3%CVE-2026-18587HIGHWavlink WL-NU516U1 Config Import os command injectionEPSS 1.3%CVE-2024-10194HIGHWAVLINK WN530H4/WN530HG4/WN572HG3 Front-End Authentication Page login.cgi Goto_chidx stack-based overflowEPSS 1.2%CVE-2024-39273CRITICALA firmware update vulnerability exists in the fw_check.sh functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP requeEPSS 1.1%CVE-2026-18590MEDIUMWavlink WL-NU516U1 Admin Password adm.cgi set_sys_adm os command injectionEPSS 1.1%CVE-2024-39789CRITICALMultiple external config control vulnerabilities exist in the nas.cgi set_ftp_cfg() functionality of Wavlink AC3000 M33A8.V5030.210505. A spEPSS 1.1%CVE-2024-39794CRITICALMultiple external config control vulnerabilities exist in the nas.cgi set_nas() proftpd functionality of Wavlink AC3000 M33A8.V5030.210505. EPSS 1.1%CVE-2024-39802CRITICALMultiple buffer overflow vulnerabilities exist in the qos.cgi qos_settings() functionality of Wavlink AC3000 M33A8.V5030.210505. A speciallyEPSS 0.9%CVE-2024-39769CRITICALMultiple buffer overflow vulnerabilities exist in the internet.cgi set_qos() functionality of Wavlink AC3000 M33A8.V5030.210505. A speciallyEPSS 0.9%CVE-2026-13539HIGHWavlink WL-NU516U1-A POST Parameter wireless.cgi sub_407504 stack-based overflowEPSS 0.9%CVE-2026-4861HIGHWavlink WL-NU516U1 nas.cgi ftext stack-based overflowEPSS 0.9%CVE-2025-5408CRITICALWAVLINK WL-WN576K1 HTTP POST Request login.cgi sys_login buffer overflowEPSS 0.8%CVE-2026-3703CRITICALWavlink NU516U1 login.cgi sub_401A10 out-of-bounds writeEPSS 0.8%CVE-2022-40621WAVLINK Quantum D4G (WN531G3) Pass-The-HashEPSS 0.8%CVE-2024-39773MEDIUMAn information disclosure vulnerability exists in the testsave.sh functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTEPSS 0.8%CVE-2026-2565HIGHWavlink WL-NU516U1 adm.cgi sub_40785C stack-based overflowEPSS 0.8%