Wavlink vendor intelligence
Wavlink Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting Wavlink products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 8
- Known exploited vulnerabilities affecting Wavlink products
- In CISA KEV
- 0
- Records also listed in the official catalog
- Beyond CISA KEV
- 8
- Additional exploited CVEs absent from CISA KEV
- Sensor Observed
- 0
- Wavlink KEVs with sensor-observed exploitation activity
The catalog gap matters for Wavlink exposure
Eight of the eight exploited Wavlink CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 100% of this vendor portfolio.
- 0%
- Covered by CISA
- 100%
- Beyond CISA
- 6
- Product families
Attested Wavlink CVEs
Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2020-12124
A remote command-line injection vulnerability in the /cgi-bin/live_api.cgi endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to... |
WN530H4 | High | Beyond CISA | 17 Mar 2026 |
|
CVE-2022-2486
WAVLINK WN535K2/WN535K3 os command injection |
WN535K2, WN535K3 | High | Beyond CISA | 18 Sep 2025 |
|
CVE-2022-2488
WAVLINK WN535K2/WN535K3 touchlist_sync.cgi os command injection |
WN535K2, WN535K3 | High | Beyond CISA | 06 Jul 2025 |
|
CVE-2022-31847
A vulnerability in /cgi-bin/ExportAllSettings.sh of WAVLINK WN579 X3 M79X3.V5030.180719 allows attackers to obtain sensitive router information via... |
WN579 X3 | High | Beyond CISA | 17 Jun 2025 |
|
CVE-2022-48164
An access control issue in the component /cgi-bin/ExportLogs.sh of Wavlink WL-WN533A8 M33A8.V5030.190716 allows unauthenticated attackers to... |
WL-WN533A8 | High | Beyond CISA | 17 Jun 2025 |
|
CVE-2020-13117
Wavlink WN575A4, WN579X3, and WN530G3A devices through 2020-05-15 allow unauthenticated remote users to inject commands via the key parameter in a... |
WN575A4, WN579X3, WN530G3A | High | Beyond CISA | 21 Jun 2025 |
|
CVE-2022-2487
WAVLINK WN535K2/WN535K3 nightled.cgi os command injection |
WN535K2, WN535K3 | High | Beyond CISA | 05 Jun 2025 |
|
CVE-2022-23900
A command injection vulnerability in the API of the Wavlink WL-WN531P3 router, version M31G3.V5030.201204, allows an attacker to achieve... |
WL-WN531P3 | High | Beyond CISA | 07 Apr 2022 |
No Wavlink CVEs match this search or filter.
Showing 8 of 8 Wavlink known exploited vulnerabilities.
Recurring weakness patterns
Neutralization, direct request ('forced browsing'), and neutralization account for seven mapped occurrences across this Wavlink KEV portfolio.
Early warning alerts
Get alerts on high-impact exploitation
Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.