CVE-2025-55847
Severity CVSS v4.0:
Pending analysis
Type:
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
26/09/2025
Last modified:
03/10/2025
Description
Wavlink M86X3A_V240730 contains a buffer overflow vulnerability in the /cgi-bin/ExportAllSettings.cgi file. The vulnerability arises because the Cookie parameter does not properly validate the length of input data. Attackers can exploit this to execute arbitrary code or cause a denial of service (DoS) on the system
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:wavlink:wl-wn586x3a_firmware:m86x3a_v240730:*:*:*:*:*:*:* | ||
| cpe:2.3:h:wavlink:wl-wn586x3a:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



