Wavlink Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for Wavlink products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
8
In CISA KEV
0
Beyond CISA KEV
8
Sensor Observed
0
Virtual Patch Available
0
Wavlink KEVs Added by Year
8 Wavlink KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2020-12124
A remote command-line injection vulnerability in the /cgi-bin/live_api.cgi endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to... |
WN530H4 | High | Not in CISA | 17 Mar 2026 |
|
CVE-2022-2486
WAVLINK WN535K2/WN535K3 os command injection |
WN535K2, WN535K3 | High | Not in CISA | 18 Sep 2025 |
|
CVE-2022-2488
WAVLINK WN535K2/WN535K3 touchlist_sync.cgi os command injection |
WN535K2, WN535K3 | High | Not in CISA | 06 Jul 2025 |
|
CVE-2022-31847
A vulnerability in /cgi-bin/ExportAllSettings.sh of WAVLINK WN579 X3 M79X3.V5030.180719 allows attackers to obtain sensitive router information via... |
WN579 X3 | High | Not in CISA | 17 Jun 2025 |
|
CVE-2022-48164
An access control issue in the component /cgi-bin/ExportLogs.sh of Wavlink WL-WN533A8 M33A8.V5030.190716 allows unauthenticated attackers to... |
WL-WN533A8 | High | Not in CISA | 17 Jun 2025 |
|
CVE-2020-13117
Wavlink WN575A4, WN579X3, and WN530G3A devices through 2020-05-15 allow unauthenticated remote users to inject commands via the key parameter in a... |
WN575A4, WN579X3, WN530G3A | High | Not in CISA | 21 Jun 2025 |
|
CVE-2022-2487
WAVLINK WN535K2/WN535K3 nightled.cgi os command injection |
WN535K2, WN535K3 | High | Not in CISA | 05 Jun 2025 |
|
CVE-2022-23900
A command injection vulnerability in the API of the Wavlink WL-WN531P3 router, version M31G3.V5030.201204, allows an attacker to achieve... |
WL-WN531P3 | High | Not in CISA | 07 Apr 2022 |
Common Vulnerability Classes (CWE)
- CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 5
- CWE-425 — Direct Request ('Forced Browsing') 1
- CWE-77 — Improper Neutralization of Special Elements used in a Command ('Command Injection') 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology