Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-50756


Wavlink WN535K3 20191010 was found to contain a command injection vulnerability in the set_sys_adm function via the newpass parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.


Published

2025-07-14T15:15:24.077

Last Modified

2025-10-03T00:43:04.920

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-77

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System wavlink wn535k3_firmware 2019-10-10 Yes
Hardware wavlink wn535k3 - No

References