CVE-2022-37149: Wavlink Wl-WN575A3 Firmware

Critical severity, CVSS 9.8. EPSS: 2.8% chance of exploitation in the next 30 days.

WAVLINK WL-WN575A3 RPT75A3.V4300.201217 was discovered to contain a command injection vulnerability when operating the file adm.cgi. This vulnerability allows attackers to execute arbitrary commands via the username parameter.

Affected products

  • Wavlink Wl-WN575A3 Firmware: version rpt75a3.v4300.201217 only

Published 2022-08-30. Last modified 2026-06-17.