Unauthenticated File Write Vulnerability in WAVLINK Routers
CVE-2026-89009
Key Information:
- Vendor
Wavlink Technology
- Vendor
- CVE Published:
- 11 September 2026
Badges
What is CVE-2026-89009?
WAVLINK WN535M1 and WN535M3 routers have a significant vulnerability that allows unauthorized users to perform arbitrary file writes. The affected routers, running firmware versions prior to M35M1_V250922, feature a sync_server daemon that listens on TCP port 13136 and operates with root privileges. This daemon does not require authentication, making it exploitable by remote attackers. By sending a specifically crafted payload, attackers can overwrite files on the device, potentially including critical startup scripts and credential storage, enabling a pathway for persistent system compromise.
Affected Version(s)
WN535M1 M35M1_V210223
WN535M3 M35M1_V210223
WN535M1 M35M1_V250922
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
