CVE-2020-10973: Wavlink WN530HG4 Firmware

High severity, CVSS 7.5. EPSS: 7.6% chance of exploitation in the next 30 days.

An issue was discovered in Wavlink WN530HG4, Wavlink WN531G3, Wavlink WN533A8, and Wavlink WN551K1 affecting /cgi-bin/ExportAllSettings.sh where a crafted POST request returns the current configuration of the device, including the administrator password. No authentication is required. The attacker must perform a decryption step, but all decryption information is readily available.

Affected products

  • Wavlink WN530HG4 Firmware: version m30hg4.v5030.191116 only
  • Wavlink WN531G3 Firmware: affected versions not specified
  • Wavlink WN533A8 Firmware: affected versions not specified
  • Wavlink WN551K1 Firmware: affected versions not specified

Published 2020-05-07. Last modified 2026-06-17.