Slew of WavLink vulnerabilities
ID: 1a839539-2ece-5a46-b6a3-203fefe2acfe
STIX ID: report--1a839539-2ece-5a46-b6a3-203fefe2acfe
Feed Name: Cisco Talos
Threat Score
### Executive Summary Cisco Talos disclosed 44 vulnerabilities (63 CVEs) in the Wavlink AC3000 router affecting multiple CGI endpoints and shell scripts, including an unauthenticated WAN-accessible static login that can yield root access via the wcrtrl service; several flaws are exploitable via specially crafted HTTP requests or MITM. Wavlink declined to patch, and Talos published Snort coverage and advisories to help detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
