Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.8

CVE-2026-89009: WAVLINK WN535M1/M3 routers allow remote file overwrite

CVE-2026-89009 · published 29 days ago
Summary

The WN535M1 and WN535M3 routers with firmware older than version M35M1_V250922 let anyone on the network replace any file on the device. The router’s sync_server service runs with full system rights and does not check who is sending data, so an attacker can change startup scripts or password files and keep control of the router. Update the router firmware to the latest version or disable the sync_server service to stop this risk.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
wavlink technology wn535m1 M35M1_V210223
wavlink technology wn535m3 M35M1_V210223
Original advisory text
WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated arbitrary file write vulnerability that allows remote attackers to overwrite any file on the d...
WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated arbitrary file write vulnerability that allows remote attackers to overwrite any file on the device by sending a crafted payload to the sync_server daemon on TCP port 13136. The daemon, which runs as root and requires no authentication, accepts a 100-byte filename field in its protocol header without path canonicalization, allowing attackers to supply an absolute path and write arbitrary content to overwrite startup scripts or credential stores to achieve persistent system compromise.
Fix within
Internet-facing 14 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker partial control
Severity
8.8 High
Exploitation
1% chance of attack within 30 days
Type
CWE-36Absolute Path Traversal
Timeline
Published11 Sep 2026
Updated7 Oct 2026
First seen11 Sep 2026
Sources
CVE-2026-89009 · MITRE
Track software like this
Free during beta