Wavlink WN535K3 20191010 was found to contain a command injection vulnerability in the set_sys_adm function via the username parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
Metrics
Affected Vendors & Products
References
History
Thu, 04 Sep 2025 18:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Wavlink wl-wn535k3
Wavlink wl-wn535k3 Firmware |
|
CPEs | cpe:2.3:h:wavlink:wl-wn535k3:-:*:*:*:*:*:*:* cpe:2.3:o:wavlink:wl-wn535k3_firmware:20191010:*:*:*:*:*:*:* |
|
Vendors & Products |
Wavlink wl-wn535k3
Wavlink wl-wn535k3 Firmware |
Wed, 03 Sep 2025 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Wavlink
Wavlink wn535k3 |
|
Vendors & Products |
Wavlink
Wavlink wn535k3 |
Tue, 02 Sep 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-77 | |
Metrics |
cvssV3_1
|
Tue, 02 Sep 2025 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Wavlink WN535K3 20191010 was found to contain a command injection vulnerability in the set_sys_adm function via the username parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-09-02T00:00:00.000Z
Updated: 2025-09-02T19:34:44.806Z
Reserved: 2025-06-16T00:00:00.000Z
Link: CVE-2025-50757

Updated: 2025-09-02T19:34:40.651Z

Status : Analyzed
Published: 2025-09-02T15:15:32.160
Modified: 2025-09-04T17:47:15.087
Link: CVE-2025-50757

No data.