Unauthenticated OS Command Injection in WAVLINK Routers
CVE-2026-89010
Key Information:
- Vendor
Wavlink Technology
- Vendor
- CVE Published:
- 11 September 2026
Badges
What is CVE-2026-89010?
WAVLINK WN535M1 and WN535M3 routers with firmware versions earlier than M35M1_V250922 are susceptible to an OS command injection vulnerability. This flaw allows attackers, without authentication, to execute arbitrary commands with root privileges by sending maliciously crafted filenames to the sync_server daemon listening on TCP port 13136. The sync_server improperly handles input that includes shell metacharacters, utilizing the unsafe sprintf() function to construct shell command strings before passing them to system(). This oversight opens a significant security breach, allowing remote exploitation of the affected devices.
Affected Version(s)
WN535M1 M35M1_V210223
WN535M3 M35M1_V210223
WN535M1 M35M1_V250922
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
