Wavlink WN535K3 Command Injection Vulnerability

Vulnerability

A command injection vulnerability has been identified in the Wavlink WN535K3 router, specifically in the 20191010 version. The issue arises in the 'set_sys_cmd' function, where the 'command' parameter can be manipulated to execute arbitrary commands on the device via a crafted request.

Impact

Exploitation of this vulnerability allows for arbitrary command execution on the affected device.

Reproduction

To reproduce this vulnerability, send a POST request to '/cgi-bin/adm.cgi' on the router's IP address. Include the 'page' parameter set to 'set_sys_cmd' and the 'command' parameter with a crafted command, such as '1;pwd;'. The request should be made with the appropriate headers to mimic a legitimate XMLHttpRequest.

Added: Sep 2, 2025, 3:23 PM
Updated: Sep 2, 2025, 8:41 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
7.5
exploitability
4.8
remediation
0.0
relevance
0.4
threat
6.5
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.