CVE-2025-55847

Severity CVSS v4.0:
Pending analysis
Type:
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
26/09/2025
Last modified:
03/10/2025

Description

Wavlink M86X3A_V240730 contains a buffer overflow vulnerability in the /cgi-bin/ExportAllSettings.cgi file. The vulnerability arises because the Cookie parameter does not properly validate the length of input data. Attackers can exploit this to execute arbitrary code or cause a denial of service (DoS) on the system

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:wavlink:wl-wn586x3a_firmware:m86x3a_v240730:*:*:*:*:*:*:*
cpe:2.3:h:wavlink:wl-wn586x3a:-:*:*:*:*:*:*:*