← Vulnerability feed

Vulnerability record · CVE-2020-13117 · published 9 February 2021

CVE-2020-13117: Wavlink router login key parameter command injection

Wavlink · Wn575a4 Firmware

Wavlink WN575A4, WN579X3 and WN530G3A devices through 2020-05-15 pass the login request 'key' parameter to a command without sanitization, allowing command injection. Because the flaw is reachable before authentication, any network-touching attacker can run commands on the device. The record does not state which firmware builds are fixed, so affected version ranges beyond the 2020-05-15 cutoff are unknown.

9.8 CVSS 3.1 Critical EPSS 69% · top 0.7% CWE-77 · Command injection
9.8CVSS 3.1 base score, v2 10.0
69%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
3References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Wavlink WN575A4, WN579X3, and WN530G3A devices through 2020-05-15 allow unauthenticated remote users to inject commands via the key parameter in a login request.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityUnauthenticated remote command execution with a 9.8 CVSS score and public exploit code, though not yet in KEV.

What it is

Wavlink WN575A4, WN579X3 and WN530G3A devices through 2020-05-15 pass the login request 'key' parameter to a command without sanitization, allowing command injection. Because the flaw is reachable before authentication, any network-touching attacker can run commands on the device. The record does not state which firmware builds are fixed, so affected version ranges beyond the 2020-05-15 cutoff are unknown.

Impact

An unauthenticated attacker gains arbitrary command execution on the device, giving full control of the router (confidentiality, integrity and availability all rated high). That position can be used to intercept or redirect traffic and to pivot into the internal network.

Attack surface

Reached over the network via the login request's key parameter; the CVSS vector is AV:N/AC:L/PR:N/UI:N, so no authentication and no user interaction are required. Any host that can reach the device's web interface can attempt it.

Exploitation

Not listed in CISA KEV, but EPSS is 0.68576 (99.3rd percentile) and two references are tagged Exploit, including a public write-up and a proof-of-concept repository, so working exploit code is publicly available.

What to do

  • Apply the vendor firmware update for WN575A4, WN579X3 and WN530G3A; the record does not name a fixed version, so confirm with Wavlink.
  • If no patch is available, remove the devices' management interface from untrusted networks and restrict access to a trusted management VLAN.
  • Disable remote/WAN administration and UPnP exposure on these devices.
  • Replace end-of-support units that will not receive firmware fixes.
  • Monitor vendor advisories for updated fixed-version information.

Detection

  • Inspect HTTP requests to the device login endpoint for shell metacharacters or command strings in the key parameter.
  • Alert on unexpected outbound connections or processes spawned by the router's web service.
  • Review device logs for login requests with abnormal key values or repeated failed logins followed by command execution.
  • Watch for configuration changes or new admin accounts on these devices.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-13117 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-3380Wavlink wn579x3 firmware injection vulnerabilityA vulnerability classified as critical has been found in Wavlink WN579X3 up to 20230615. Affected is an unknown function of the file /cgi-bin/adm.cgi…EPSS 3.9%7.5CVE-2022-31847Wavlink wn579x3 firmware vulnerabilityA vulnerability in /cgi-bin/ExportAllSettings.sh of WAVLINK WN579 X3 M79X3.V5030.180719 allows attackers to obtain sensitive router information via a…EPSS 6.6%7.5CVE-2020-10974Wavlink wl-wn575a3 firmware missing authentication for critical function vulnerabilityAn issue was discovered affecting a backup feature where a crafted POST request returns the current configuration of the device in cleartext, includi…EPSS 1.7%7.5CVE-2020-12266Wavlink wl-wn579g3 firmware missing authentication for critical function vulnerabilityAn issue was discovered where there are multiple externally accessible pages that do not require any sort of authentication, and store system informa…EPSS 1.8%9.8CVE-2026-8037Progress LoadMaster API OS Command Injection RCEProgress LoadMaster (and related ADC products) contain an OS command injection flaw in multiple API command endpoints where unsanitized input is pass…KEVEPSS 77%analysed8.7CVE-2026-42271LiteLLM MCP test endpoints allow authenticated OS command injectionLiteLLM versions 1.74.2 through before 1.83.7 expose two MCP preview endpoints (POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list) th…KEVEPSS 13%analysed7.2CVE-2025-29635D-Link DIR-823X command injection in set_prohibiting handlerD-Link DIR-823X firmware (240126 and 240802) contains a command injection flaw in the /goform/set_prohibiting POST handler. An attacker who already h…KEVEPSS 88%analysed8.1CVE-2026-22719VMware Aria Operations command injection during support-assisted migrationVMware Aria Operations contains a command injection flaw (CWE-77) that an unauthenticated attacker can use to run arbitrary commands, potentially ach…KEVEPSS 18%analysed

Source: NIST National Vulnerability Database (record CVE-2020-13117), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.