Wavlink AC1200 with firmware versions M32A3_V1410_230602...
Moderate severity
Unreviewed
Published
Sep 2, 2025
to the GitHub Advisory Database
•
Updated Sep 2, 2025
Description
Published by the National Vulnerability Database
Sep 2, 2025
Published to the GitHub Advisory Database
Sep 2, 2025
Last updated
Sep 2, 2025
Wavlink AC1200 with firmware versions M32A3_V1410_230602 and M32A3_V1410_240222 are vulnerable to a post-authentication command injection while resetting the password. This vulnerability is specifically found within the "set_sys_adm" function of the "adm.cgi" binary, and is due to improper santization of the user provided "newpass" field
References