CVE-2024-38894: Wavlink WN551K1 Firmware

Medium severity, CVSS 5.3. EPSS: 1.2% chance of exploitation in the next 30 days.

WAVLINK WN551K1 found a command injection vulnerability through the IP parameter of /cgi-bin/touchlist_sync.cgi.

Affected products

  • Wavlink WN551K1 Firmware: affected versions not specified

Published 2024-06-24. Last modified 2026-06-17.