CVE-2025-25528: Wavlink Wl-WN575A3 Firmware

Medium severity, CVSS 5.1. EPSS: 3.9% chance of exploitation in the next 30 days.

Multiple buffer overflow vulnerabilities in Wavlink WL-WN575A3 RPT75A3.V4300, which are caused by not performing strict length checks on user-controlled data. By successfully exploiting the vulnerabilities, attackers can crash the remote devices or execute arbitrary commands without any authorization verification.

Affected products

  • Wavlink Wl-WN575A3 Firmware: version rpt75a3.v4300 only

Published 2025-02-11. Last modified 2026-06-17.