CVE-2020-13117: Wavlink WN575A4 Firmware

Critical severity, CVSS 9.8. EPSS: 68.6% chance of exploitation in the next 30 days.

Wavlink WN575A4, WN579X3, and WN530G3A devices through 2020-05-15 allow unauthenticated remote users to inject commands via the key parameter in a login request.

Affected products

  • Wavlink WN575A4 Firmware: up to and including 2020-05-15
  • Wavlink WN579X3 Firmware: up to and including 2020-05-15

Published 2021-02-09. Last modified 2026-06-17.