CVE-2020-10973: Wavlink WN530HG4 Firmware
High severity, CVSS 7.5. EPSS: 7.6% chance of exploitation in the next 30 days.
An issue was discovered in Wavlink WN530HG4, Wavlink WN531G3, Wavlink WN533A8, and Wavlink WN551K1 affecting /cgi-bin/ExportAllSettings.sh where a crafted POST request returns the current configuration of the device, including the administrator password. No authentication is required. The attacker must perform a decryption step, but all decryption information is readily available.
Affected products
- Wavlink WN530HG4 Firmware: version m30hg4.v5030.191116 only
- Wavlink WN531G3 Firmware: affected versions not specified
- Wavlink WN533A8 Firmware: affected versions not specified
- Wavlink WN551K1 Firmware: affected versions not specified
Published 2020-05-07. Last modified 2026-06-17.