WAVLINK WN535M1 和 WN535M3 路由器中,在运行早于 M35M1_V250922 版本的固件时,存在一个无需身份验证的操作系统命令注入漏洞。远程攻击者可以通过向运行在 TCP 端口 13136 上的 sync_server 守护进程发送特制的文件名,从而以 root 权限执行任意命令。该守护进程通过 sprintf() 将包含 shell 元字符的攻击者可控的文件名输入插入到一个 shell 命令字符串中,并在未经过任何净化处理的情况下将其传递给 system() 函数,从而实现了在设备上的 r
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| WAVLINK Technology | WN535M1 | M35M1_V210223 | - |
|
| WAVLINK Technology | WN535M3 | M35M1_V210223 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet