CVE-2024-48705: Wavlink Wl-WN531P3 Firmware

Medium severity, CVSS 6.5. EPSS: 3.4% chance of exploitation in the next 30 days.

Wavlink AC1200 with firmware versions M32A3_V1410_230602 and M32A3_V1410_240222 are vulnerable to a post-authentication command injection while resetting the password. This vulnerability is specifically found within the "set_sys_adm" function of the "adm.cgi" binary, and is due to improper santization of the user provided "newpass" field

Affected products

  • Wavlink Wl-WN531P3 Firmware: version m32a3_v1410_230602 only; version m32a3_v1410_240222 only

Published 2025-09-02. Last modified 2026-07-05.