Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-89010: Wavlink WN535M1 and WN535M3 routers allow remote code execution
CVE-2026-89010 · published 29 days ago
Summary
These routers can be tricked into running any command as the system administrator by sending a specially crafted file name to a service on port 13136. An attacker could take full control of the device without needing a password. Update the router firmware to the version released after M35M1_V250922 or later, and consider blocking external access to the affected port until the update is applied.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| wavlink technology | wn535m1 | M35M1_V210223 |
| wavlink technology | wn535m3 | M35M1_V210223 |
Original advisory text
WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary commands ...
WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted filenames to the sync_server daemon on TCP port 13136. The daemon interpolates attacker-controlled filename input containing shell metacharacters into a shell command string via sprintf() and passes it to system() without sanitization, enabling root-level command execution on the device.
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Severity
9.3
Critical
Type
CWE-78OS Command Injection
Timeline
Published11 Sep 2026
Updated4 Oct 2026
First seen11 Sep 2026
Track software like this
Free during beta