Wavlink manufactures a range of consumer and small-business networking devices, particularly wireless access points and range extenders, that are widely deployed in residential and office environments. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting both the embedded nature of the firmware and the internet-facing attack surface these devices present. The exposure concentrates in its WN533A8 access point line and related firmware, and recurs persistently through command-injection variants, buffer overflows, and output-encoding flaws that are characteristic of firmware with inadequate input sanitization. Defenders should inventory affected Wavlink devices on their networks and prioritize firmware updates, as the combination of critical severity and public exploit availability creates significant risk from remote compromise. Current exploitation activity, KEV status, and detailed severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wavlink over time
Signals from CVEs in this vendor scope (203 CVEs).
203 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-2487CRITICAL A vulnerability has been found in WAVLINK WN535K2 and WN535K3 and classified as critical. This vulnerability affects unknown code of the file /cgi-bin/nightled.cgi. The manipulatio | Jul 20, 2022 | 9.8 | 83 | NO | YES |
CVE-2020-13117CRITICAL Wavlink WN575A4, WN579X3, and WN530G3A devices through 2020-05-15 allow unauthenticated remote users to inject commands via the key parameter in a login request. | Feb 9, 2021 | 9.8 | 77 | NO | YES |
CVE-2020-12124CRITICAL A remote command-line injection vulnerability in the /cgi-bin/live_api.cgi endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to execute arbitrary Linux commands | Oct 2, 2020 | 9.8 | 75 | NO | YES |
CVE-2022-2488CRITICAL A vulnerability was found in WAVLINK WN535K2 and WN535K3 and classified as critical. This issue affects some unknown processing of the file /cgi-bin/touchlist_sync.cgi. The manipul | Jul 20, 2022 | 9.8 | 60 | NO | YES |
CVE-2022-2486CRITICAL A vulnerability, which was classified as critical, was found in WAVLINK WN535K2 and WN535K3. This affects an unknown part of the file /cgi-bin/mesh.cgi?page=upgrade. The manipulati | Jul 20, 2022 | 9.8 | 60 | NO | YES |
CVE-2022-34047HIGH An access control issue in Wavlink WN530HG4 M30HG4.V5030.191116 allows attackers to obtain usernames and passwords via view-source:http://IP_ADDRESS/set_safety.shtml?r=52300 and se | Jul 20, 2022 | 7.5 | 55 | NO | YES |
CVE-2022-34046HIGH An access control issue in Wavlink WN533A8 M33A8.V5030.190716 allows attackers to obtain usernames and passwords via view-source:http://IP_ADDRESS/sysinit.shtml?r=52300 and searchi | Jul 20, 2022 | 7.5 | 55 | NO | YES |
CVE-2024-39280CRITICAL An external config control vulnerability exists in the nas.cgi set_smb_cfg() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitr | Jan 14, 2025 | 9.1 | 41 | NO | NO |
CVE-2022-34048MEDIUM Wavlink WN533A8 M33A8.V5030.190716 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the login_page parameter. | Jul 20, 2022 | 6.1 | 41 | NO | YES |
CVE-2022-34045CRITICAL Wavlink WN530HG4 M30HG4.V5030.191116 was discovered to contain a hardcoded encryption/decryption key for its configuration files at /etc_ro/lighttpd/www/cgi-bin/ExportAllSettings.s | Jul 20, 2022 | 9.8 | 41 | NO | YES |
Signals from CVEs in this vendor scope (203 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wavlink.
Media articles that mention a CVE ID that affects a product developed by Wavlink — matched by CVE ID, not by vendor name.