Wavlink WN575A4 and WN579X3 devices through 2020-05-15 allow unauthenticated remote users to inject commands via the key parameter in a login request.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13117
Reference (s):
- https://blog.0xlabs.com/2021/02/wavlink-rce-CVE-2020-13117.html

