Server-side Security Vulnerability in WL-WN531AX2 Firmware by Wavlink
CVE-2023-32612

7.2HIGH

Key Information:

Vendor
CVE Published:
30 June 2023

What is CVE-2023-32612?

A vulnerability exists in the WL-WN531AX2 firmware that allows an attacker with administrative privileges to execute OS commands with root access. This weakness is a result of improper enforcement of server-side security checks on the client side, enabling unauthorized command execution that could lead to a full compromise of the device. Users are advised to update their firmware to the latest version (2023526 or later) to mitigate this risk.

Affected Version(s)

WL-WN531AX2 firmware versions prior to 2023526

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.