CVE-2020-13117 Scanner

Targets the login endpoint's key parameter to inject OS commands, enabling unauthenticated remote code execution on the router.

Short Info


Level

Critical

Single Scan

Single Scan

Can be used by

Asset Owner

Estimated Time

10 seconds

Time Interval

8 days 3 hours

Scan only one

Domain, IPv4, Subdomain

Toolbox

Wavlink WN575A4 and WN579X3 are dual-band wireless routers designed for home and small office use, providing high-speed internet, guest network access, and parental controls. They are popular for their affordability and ease of setup, making them common in residential and small business environments.

CVE-2020-13117 is a critical command injection vulnerability that arises from insufficient input sanitization in the router's login mechanism. The key parameter in login requests is passed directly to system-level commands without proper validation, allowing attackers to inject arbitrary OS commands.

Specifically, the vulnerability exists in the login endpoint where the key parameter is processed. An unauthenticated attacker can send a crafted HTTP POST request to the router's login page, injecting commands via the key field, which are then executed with root privileges on the device.

Successful exploitation grants full remote control of the router, enabling attackers to monitor traffic, steal credentials, modify DNS settings, or use the device as a pivot for further network attacks. This can lead to data breaches, network compromise, and loss of privacy.

Get started to protecting your digital assets