Vulnerability record · CVE-2020-12124 · published 2 October 2020
CVE-2020-12124: WAVLINK WN530H4 live_api.cgi unauthenticated root command injection
Wavlink · Wn530h4 Firmware
The /cgi-bin/live_api.cgi endpoint on the WAVLINK WN530H4 (firmware M30H4.V5030.190403) passes input to a shell without sanitisation, allowing OS command injection. Because the endpoint is reachable without authentication and commands run as root, any network-reachable device is at risk of full compromise.
Description
A remote command-line injection vulnerability in the /cgi-bin/live_api.cgi endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to execute arbitrary Linux commands as root without authentication.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote command execution as root with a CVSS score of 9.8 and very high EPSS probability makes this an urgent exposure for any internet-reachable WN530H4.
What it is
The /cgi-bin/live_api.cgi endpoint on the WAVLINK WN530H4 (firmware M30H4.V5030.190403) passes input to a shell without sanitisation, allowing OS command injection. Because the endpoint is reachable without authentication and commands run as root, any network-reachable device is at risk of full compromise.
Impact
An attacker gains arbitrary command execution as root on the router, enabling full control of the device, interception or redirection of traffic, and use of the device as a foothold into the internal network.
Attack surface
Reachable over the network via HTTP requests to /cgi-bin/live_api.cgi; the CVSS vector (AV:N/PR:N/UI:N) indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV and no ransomware associations are recorded, but EPSS is very high (0.7465, ~99.5th percentile), indicating substantial predicted exploitation activity; references are only third-party and vendor advisories, with no public exploit tag.
What to do
- Apply the latest WAVLINK firmware for the WN530H4 if the vendor has released a fix; if no patch exists, treat the device as end-of-life and replace it.
- Block external and untrusted access to the router's web management interface, including /cgi-bin/live_api.cgi, at the firewall or by disabling remote administration.
- Place the device on an isolated network segment or VLAN so a compromise cannot reach other internal hosts.
- If the device must remain in use, restrict management access to a trusted administrative network only and monitor it closely.
Detection
- Inspect HTTP request logs or packet captures for requests to /cgi-bin/live_api.cgi containing shell metacharacters (;, |, $(), backticks) or unexpected command strings.
- Monitor router and upstream logs for outbound connections or processes spawned by the web server that are inconsistent with normal device behaviour.
- Alert on repeated or anomalous requests to /cgi-bin/live_api.cgi from external or non-administrative source addresses.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://cerne.xyz/bugs/CVE-2020-12124 | Third Party Advisory |
| https://www.wavlink.com/en_us/product/WL-WN530H4.html | ProductVendor Advisory |
| https://cerne.xyz/bugs/CVE-2020-12124 | Third Party Advisory |
| https://www.wavlink.com/en_us/product/WL-WN530H4.html | ProductVendor Advisory |
Track CVE-2020-12124 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-12124), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.