Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-89010: Wavlink WN535M1 and WN535M3 routers allow remote code execution

CVE-2026-89010 · published 29 days ago
Summary

These routers can be tricked into running any command as the system administrator by sending a specially crafted file name to a service on port 13136. An attacker could take full control of the device without needing a password. Update the router firmware to the version released after M35M1_V250922 or later, and consider blocking external access to the affected port until the update is applied.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
wavlink technology wn535m1 M35M1_V210223
wavlink technology wn535m3 M35M1_V210223
Original advisory text
WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary commands ...
WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted filenames to the sync_server daemon on TCP port 13136. The daemon interpolates attacker-controlled filename input containing shell metacharacters into a shell command string via sprintf() and passes it to system() without sanitization, enabling root-level command execution on the device.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.3 Critical
Exploitation
3% chance of attack within 30 days
Type
CWE-78OS Command Injection
Timeline
Published11 Sep 2026
Updated4 Oct 2026
First seen11 Sep 2026
Sources
CVE-2026-89010 · MITRE
Track software like this
Free during beta