CVE-2026-89010 | WAVLINK WN535M1/WN535M3 up to M35M1_V210223 sync_server system filenames os command injection
A vulnerability categorized as very critical has been discovered in WAVLINK WN535M1 and WN535M3 up to M35M1_V210223. The affected element is the function system of the component sync_server. Such manipulation of the argument filenames leads to os command injection. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is uniquely identified as CVE-2026-89010. The attack can be launched remotely. No exploit exists.
It is advisable to upgrade the affected component.VulDB Recent EntriesRead More