CVE-2020-12123: Wavlink WN530H4 Firmware
High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.
CSRF vulnerabilities in the /cgi-bin/ directory of the WAVLINK WN530H4 M30H4.V5030.190403 allow an attacker to remotely access router endpoints, because these endpoints do not contain CSRF tokens. If a user is authenticated in the router portal, then this attack will work.
Affected products
- Wavlink WN530H4 Firmware: version m30h4.v5030.190403 only
Published 2020-10-02. Last modified 2026-06-17.