CVE-2020-15489: Wavlink Wl-WN530HG4 Firmware

Critical severity, CVSS 9.8. EPSS: 3.7% chance of exploitation in the next 30 days.

An issue was discovered on Wavlink WL-WN530HG4 M30HG4.V5030.191116 devices. Multiple shell metacharacter injection vulnerabilities exist in CGI scripts, leading to remote code execution with root privileges.

Affected products

  • Wavlink Wl-WN530HG4 Firmware: version m30hg4.v5030.191116 only

Published 2020-07-01. Last modified 2026-06-17.