Vulnerability Details CVE-2020-13117
Wavlink WN575A4 and WN579X3 devices through 2020-05-15 allow unauthenticated remote users to inject commands via the key parameter in a login request.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.93
EPSS Ranking 99.8%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 10.0
Products affected by CVE-2020-13117
-
cpe:2.3:h:wavlink:wn575a4:-
-
cpe:2.3:h:wavlink:wn579x3:-
-
cpe:2.3:o:wavlink:wn575a4_firmware:-
-
cpe:2.3:o:wavlink:wn575a4_firmware:2020-05-15
-
cpe:2.3:o:wavlink:wn579x3_firmware:-
-
cpe:2.3:o:wavlink:wn579x3_firmware:2020-05-15