Wavlink
Wavlink Wn551k1 Firmware: vulnerabilidades y CVE
Wavlink Wn551k1 Firmware tiene 7 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-38897 | Media (5.3) | 0.40% | — | 24 jun 2024 | WAVLINK WN551K1'live_check.shtml enables attackers to obtain sensitive router information. |
| CVE-2024-38896 | Media (5.3) | 1.2% | — | 24 jun 2024 | WAVLINK WN551K1 found a command injection vulnerability through the start_hour parameter of /cgi-bin/nightled.cgi. |
| CVE-2024-38895 | Media (5.3) | 0.39% | — | 24 jun 2024 | WAVLINK WN551K1'live_mfg.shtml enables attackers to obtain sensitive router information. |
| CVE-2024-38894 | Media (5.3) | 1.2% | — | 24 jun 2024 | WAVLINK WN551K1 found a command injection vulnerability through the IP parameter of /cgi-bin/touchlist_sync.cgi. |
| CVE-2024-38892 | Media (6.5) | 0.39% | — | 24 jun 2024 | An issue in Wavlink WN551K1 allows a remote attacker to obtain sensitive information via the ExportAllSettings.sh component. |
| CVE-2020-10973 | Alta (7.5) | 7.6% | — | 7 may 2020 | An issue was discovered in Wavlink WN530HG4, Wavlink WN531G3, Wavlink WN533A8, and Wavlink WN551K1 affecting /cgi-bin/ExportAllSettings.sh where a crafted POST request returns the current configuration of the device,… |
| CVE-2020-12266 | Alta (7.5) | 1.8% | — | 27 abr 2020 | An issue was discovered where there are multiple externally accessible pages that do not require any sort of authentication, and store system information for internal usage. The devices automatically query these pages… |