Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Wavlink

First CVE: Apr 27, 2020Active for: 6 yearsTotal CVEs: 203
60.0
VTI Score
TOP TARGET

Wavlink manufactures a range of consumer and small-business networking devices, particularly wireless access points and range extenders, that are widely deployed in residential and office environments. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting both the embedded nature of the firmware and the internet-facing attack surface these devices present. The exposure concentrates in its WN533A8 access point line and related firmware, and recurs persistently through command-injection variants, buffer overflows, and output-encoding flaws that are characteristic of firmware with inadequate input sanitization. Defenders should inventory affected Wavlink devices on their networks and prioritize firmware updates, as the combination of critical severity and public exploit availability creates significant risk from remote compromise. Current exploitation activity, KEV status, and detailed severity counts are shown alongside this summary.

FAUCET AI Generated
203
Total CVEs
More Total CVEs than 100% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
8.1
Avg CVSS Score
Higher Avg CVSS Score than 78% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Wavlink over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 27, 2020
6 years ago
Most Recent CVE
May 10, 2026
74 days ago

Products(76 total)

Top CVEs

Signals from CVEs in this vendor scope (203 CVEs).

203 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-2487CRITICAL
A vulnerability has been found in WAVLINK WN535K2 and WN535K3 and classified as critical. This vulnerability affects unknown code of the file /cgi-bin/nightled.cgi. The manipulatio
Jul 20, 20229.883NOYES
CVE-2020-13117CRITICAL
Wavlink WN575A4, WN579X3, and WN530G3A devices through 2020-05-15 allow unauthenticated remote users to inject commands via the key parameter in a login request.
Feb 9, 20219.877NOYES
CVE-2020-12124CRITICAL
A remote command-line injection vulnerability in the /cgi-bin/live_api.cgi endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to execute arbitrary Linux commands
Oct 2, 20209.875NOYES
CVE-2022-2488CRITICAL
A vulnerability was found in WAVLINK WN535K2 and WN535K3 and classified as critical. This issue affects some unknown processing of the file /cgi-bin/touchlist_sync.cgi. The manipul
Jul 20, 20229.860NOYES
CVE-2022-2486CRITICAL
A vulnerability, which was classified as critical, was found in WAVLINK WN535K2 and WN535K3. This affects an unknown part of the file /cgi-bin/mesh.cgi?page=upgrade. The manipulati
Jul 20, 20229.860NOYES
CVE-2022-34047HIGH
An access control issue in Wavlink WN530HG4 M30HG4.V5030.191116 allows attackers to obtain usernames and passwords via view-source:http://IP_ADDRESS/set_safety.shtml?r=52300 and se
Jul 20, 20227.555NOYES
CVE-2022-34046HIGH
An access control issue in Wavlink WN533A8 M33A8.V5030.190716 allows attackers to obtain usernames and passwords via view-source:http://IP_ADDRESS/sysinit.shtml?r=52300 and searchi
Jul 20, 20227.555NOYES
CVE-2024-39280CRITICAL
An external config control vulnerability exists in the nas.cgi set_smb_cfg() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitr
Jan 14, 20259.141NONO
CVE-2022-34048MEDIUM
Wavlink WN533A8 M33A8.V5030.190716 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the login_page parameter.
Jul 20, 20226.141NOYES
CVE-2022-34045CRITICAL
Wavlink WN530HG4 M30HG4.V5030.191116 was discovered to contain a hardcoded encryption/decryption key for its configuration files at /etc_ro/lighttpd/www/cgi-bin/ExportAllSettings.s
Jul 20, 20229.841NOYES
View all 203 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products203 CVEs
13%
57%
30%
Severity distribution among all CVEs352,101 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (0.5%)
Network190 (93.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network12 (5.9%)
Attack Complexity
Low199 (98.0%)
High4 (2.0%)
Unknown0 (0.0%)
User Interaction
None195 (96.1%)
Unknown0 (0.0%)
Required8 (3.9%)
Privileges Required
Low32 (15.8%)
High67 (33.0%)
None104 (51.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (203 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
23 CVEs
11.3% of CVEs· 96th percentile
ExploitDB
3 CVEs
1.5% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Wavlink.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Wavlink — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Wavlink's Products

View all 5 CNAs →

Top CWEs