Wavlink WN575A4 and WN579X3 devices through 2020-05-15 allow unauthenticated remote users to inject commands via the key parameter in a login request.
References
Link Resource
https://blog.0xlabs.com/2021/02/wavlink-rce-CVE-2020-13117.html Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2021-02-09T18:53:18

Updated: 2021-02-09T18:53:18

Reserved: 2020-05-16T00:00:00


Link: CVE-2020-13117

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-02-09T19:15:13.460

Modified: 2021-02-12T21:08:06.480


Link: CVE-2020-13117

JSON object: View

cve-icon Redhat Information

No data.

CWE