Vulnerability Description
Wavlink WN575A4, WN579X3, and WN530G3A devices through 2020-05-15 allow unauthenticated remote users to inject commands via the key parameter in a login request.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wavlink | Wn575A4 Firmware | <= 2020-05-15 |
| Wavlink | Wn575A4 | - |
| Wavlink | Wn579X3 Firmware | <= 2020-05-15 |
| Wavlink | Wn579X3 | - |
Related Weaknesses (CWE)
References
- https://blog.0xlabs.com/2021/02/wavlink-rce-CVE-2020-13117.htmlExploitThird Party Advisory
- https://github.com/ice-wzl/Wavlink-WN530G3A-Cmd-Injection/blob/main/README.md
- https://blog.0xlabs.com/2021/02/wavlink-rce-CVE-2020-13117.htmlExploitThird Party Advisory
FAQ
What is CVE-2020-13117?
CVE-2020-13117 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Wavlink WN575A4, WN579X3, and WN530G3A devices through 2020-05-15 allow unauthenticated remote users to inject commands via the key parameter in a login request.
How severe is CVE-2020-13117?
CVE-2020-13117 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-13117?
Check the references section above for vendor advisories and patch information. Affected products include: Wavlink Wn575A4 Firmware, Wavlink Wn575A4, Wavlink Wn579X3 Firmware, Wavlink Wn579X3.