← Vulnerability feed

Vulnerability record · CVE-2024-54747 · published 6 December 2024

CVE-2024-54747: Wavlink wn531p3 firmware incorrect default permissions vulnerability

Wavlink · Wn531p3 Firmware

WAVLINK WN531P3 202383 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.

9.8 CVSS 3.1 Critical EPSS 0.56% · top 55.7% CWE-276 · Incorrect default permissions
9.8CVSS 3.1 base score
0.56%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

WAVLINK WN531P3 202383 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-54747 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-35534Wavlink wn572hp3 firmware vulnerabilityWAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 wireless.cgi has no filtering on parameter hiddenSSID32g and SSID2G2, which leads to command inj…EPSS 2.3%9.8CVE-2022-35535Wavlink wn572hp3 firmware vulnerabilityWAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 wireless.cgi has no filtering on parameter macAddr, which leads to command injection in page /wi…EPSS 2.3%9.8CVE-2022-35536Wavlink wn572hp3 firmware vulnerabilityWAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 qos.cgi has no filtering on parameters: qos_bandwith and qos_dat, which leads to command injecti…EPSS 2.2%9.8CVE-2022-35537Wavlink wn572hp3 firmware vulnerabilityWAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 wireless.cgi has no filtering on parameters: mac_5g and Newname, which leads to command injectio…EPSS 2.2%9.8CVE-2022-35538Wavlink wn572hp3 firmware vulnerabilityWAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 wireless.cgi has no filtering on parameters: delete_list, delete_al_mac, b_delete_list and b_del…EPSS 2.2%9.8CVE-2022-35524Wavlink wn572hp3 firmware vulnerabilityWAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 adm.cgi has no filtering on parameters: wlan_signal, web_pskValue, sel_EncrypTyp, sel_Automode, …EPSS 2.3%9.8CVE-2022-35525Wavlink wn572hp3 firmware vulnerabilityWAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 adm.cgi has no filtering on parameter led_switch, which leads to command injection in page /ledo…EPSS 2.4%9.8CVE-2022-35526Wavlink wn572hp3 firmware vulnerabilityWAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 login.cgi has no filtering on parameter key, which leads to command injection in page /login.sht…EPSS 2.3%

Source: NIST National Vulnerability Database (record CVE-2024-54747), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.