← Vulnerability feed

Vulnerability record · CVE-2020-12124 · published 2 October 2020

CVE-2020-12124: WAVLINK WN530H4 live_api.cgi unauthenticated root command injection

Wavlink · Wn530h4 Firmware

The /cgi-bin/live_api.cgi endpoint on the WAVLINK WN530H4 (firmware M30H4.V5030.190403) passes input to a shell without sanitisation, allowing OS command injection. Because the endpoint is reachable without authentication and commands run as root, any network-reachable device is at risk of full compromise.

9.8 CVSS 3.1 Critical EPSS 75% · top 0.5% CWE-78 · OS command injection
9.8CVSS 3.1 base score, v2 10.0
75%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

A remote command-line injection vulnerability in the /cgi-bin/live_api.cgi endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to execute arbitrary Linux commands as root without authentication.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated remote command execution as root with a CVSS score of 9.8 and very high EPSS probability makes this an urgent exposure for any internet-reachable WN530H4.

What it is

The /cgi-bin/live_api.cgi endpoint on the WAVLINK WN530H4 (firmware M30H4.V5030.190403) passes input to a shell without sanitisation, allowing OS command injection. Because the endpoint is reachable without authentication and commands run as root, any network-reachable device is at risk of full compromise.

Impact

An attacker gains arbitrary command execution as root on the router, enabling full control of the device, interception or redirection of traffic, and use of the device as a foothold into the internal network.

Attack surface

Reachable over the network via HTTP requests to /cgi-bin/live_api.cgi; the CVSS vector (AV:N/PR:N/UI:N) indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV and no ransomware associations are recorded, but EPSS is very high (0.7465, ~99.5th percentile), indicating substantial predicted exploitation activity; references are only third-party and vendor advisories, with no public exploit tag.

What to do

  • Apply the latest WAVLINK firmware for the WN530H4 if the vendor has released a fix; if no patch exists, treat the device as end-of-life and replace it.
  • Block external and untrusted access to the router's web management interface, including /cgi-bin/live_api.cgi, at the firewall or by disabling remote administration.
  • Place the device on an isolated network segment or VLAN so a compromise cannot reach other internal hosts.
  • If the device must remain in use, restrict management access to a trusted administrative network only and monitor it closely.

Detection

  • Inspect HTTP request logs or packet captures for requests to /cgi-bin/live_api.cgi containing shell metacharacters (;, |, $(), backticks) or unexpected command strings.
  • Monitor router and upstream logs for outbound connections or processes spawned by the web server that are inconsistent with normal device behaviour.
  • Alert on repeated or anomalous requests to /cgi-bin/live_api.cgi from external or non-administrative source addresses.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-12124 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-35534Wavlink wn572hp3 firmware vulnerabilityWAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 wireless.cgi has no filtering on parameter hiddenSSID32g and SSID2G2, which leads to command inj…EPSS 2.3%9.8CVE-2022-35535Wavlink wn572hp3 firmware vulnerabilityWAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 wireless.cgi has no filtering on parameter macAddr, which leads to command injection in page /wi…EPSS 2.3%9.8CVE-2022-35536Wavlink wn572hp3 firmware vulnerabilityWAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 qos.cgi has no filtering on parameters: qos_bandwith and qos_dat, which leads to command injecti…EPSS 2.2%9.8CVE-2022-35537Wavlink wn572hp3 firmware vulnerabilityWAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 wireless.cgi has no filtering on parameters: mac_5g and Newname, which leads to command injectio…EPSS 2.2%9.8CVE-2022-35538Wavlink wn572hp3 firmware vulnerabilityWAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 wireless.cgi has no filtering on parameters: delete_list, delete_al_mac, b_delete_list and b_del…EPSS 2.2%9.8CVE-2022-35524Wavlink wn572hp3 firmware vulnerabilityWAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 adm.cgi has no filtering on parameters: wlan_signal, web_pskValue, sel_EncrypTyp, sel_Automode, …EPSS 2.3%9.8CVE-2022-35525Wavlink wn572hp3 firmware vulnerabilityWAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 adm.cgi has no filtering on parameter led_switch, which leads to command injection in page /ledo…EPSS 2.4%9.8CVE-2022-35526Wavlink wn572hp3 firmware vulnerabilityWAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 login.cgi has no filtering on parameter key, which leads to command injection in page /login.sht…EPSS 2.3%

Source: NIST National Vulnerability Database (record CVE-2020-12124), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.