CVE-2026-89009
moderateUnauthenticated Arbitrary File Write in WAVLINK WN535M1/WN535M3 Routers
WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated arbitrary file write (CWE-36, absolute path traversal) in the sync_server daemon, which listens on TCP port 13136 and runs as root with no authentication. A remote attacker sends a crafted payload whose 100-byte filename field is accepted without path canonicalization, allowing an absolute path so arbitrary content can be written to any location on the device's filesystem. By overwriting startup scripts or credential stores, an attacker can persist across reboots and achieve full, persistent compromise of the router as root. Only deployments of these two WAVLINK router models on affected firmware are impacted. No public proof-of-concept, KEV listing, or reported in-the-wild exploitation is currently known, though the CVSS 4.0 score of 8.8 (High) reflects serious network-reachable impact.
What to do: Upgrade WN535M1 and WN535M3 units to firmware M35M1_V250922 or later. Until patched, block or firewall inbound TCP port 13136 from WAN/untrusted networks, since the sync_server daemon requires no authentication. Because the flaw permits root-level file writes, internet-exposed devices should be inspected for tampered startup scripts or altered credentials and treated as potentially compromised if they were reachable on that port.
| WAVLINK WN535M1 router | firmware prior to M35M1_V250922 |
| WAVLINK WN535M3 router | firmware prior to M35M1_V250922 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated arbitrary file write vulnerability that allows remote attackers to overwrite any file on the device by sending a crafted payload to the sync_server daemon on TCP port 13136. The daemon, which runs as root and requires no authentication, accepts a 100-byte filename field in its protocol header without path canonicalization, allowing attackers to supply an absolute path and write arbitrary content to overwrite startup scripts or credential stores to achieve persistent system compromise.
- Weakness
- CWE-36
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.