← Vulnerability feed

Vulnerability record · CVE-2020-12127 · published 2 October 2020

CVE-2020-12127: Wavlink wn530h4 firmware missing authentication for critical function vulnerability

Wavlink · Wn530h4 Firmware

An information disclosure vulnerability in the /cgi-bin/ExportAllSettings.sh endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to leak router settings, including cleartext login details, DNS settings, and other sensitive information without authentication.

7.5 CVSS 3.1 High EPSS 7.4% · top 5.8% CWE-306 · Missing authentication for critical function
7.5CVSS 3.1 base score, v2 5.0
7.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

An information disclosure vulnerability in the /cgi-bin/ExportAllSettings.sh endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to leak router settings, including cleartext login details, DNS settings, and other sensitive information without authentication.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-12127 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-35534Wavlink wn572hp3 firmware vulnerabilityWAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 wireless.cgi has no filtering on parameter hiddenSSID32g and SSID2G2, which leads to command inj…EPSS 2.3%9.8CVE-2022-35535Wavlink wn572hp3 firmware vulnerabilityWAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 wireless.cgi has no filtering on parameter macAddr, which leads to command injection in page /wi…EPSS 2.3%9.8CVE-2022-35536Wavlink wn572hp3 firmware vulnerabilityWAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 qos.cgi has no filtering on parameters: qos_bandwith and qos_dat, which leads to command injecti…EPSS 2.2%9.8CVE-2022-35537Wavlink wn572hp3 firmware vulnerabilityWAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 wireless.cgi has no filtering on parameters: mac_5g and Newname, which leads to command injectio…EPSS 2.2%9.8CVE-2022-35538Wavlink wn572hp3 firmware vulnerabilityWAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 wireless.cgi has no filtering on parameters: delete_list, delete_al_mac, b_delete_list and b_del…EPSS 2.2%9.8CVE-2022-35524Wavlink wn572hp3 firmware vulnerabilityWAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 adm.cgi has no filtering on parameters: wlan_signal, web_pskValue, sel_EncrypTyp, sel_Automode, …EPSS 2.3%9.8CVE-2022-35525Wavlink wn572hp3 firmware vulnerabilityWAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 adm.cgi has no filtering on parameter led_switch, which leads to command injection in page /ledo…EPSS 2.4%9.8CVE-2022-35526Wavlink wn572hp3 firmware vulnerabilityWAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 login.cgi has no filtering on parameter key, which leads to command injection in page /login.sht…EPSS 2.3%

Source: NIST National Vulnerability Database (record CVE-2020-12127), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.