boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-89009

WAVLINK WN535M1/WN535M3 Unauthenticated Arbitrary File Write via sync_server
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   H   H    8.8   .0101   61.9     —
AFFECTED
  Product  Versions         Fixed
  WN535M1  M35M1_V210223 –  M35M1_V250922
  WN535M3  M35M1_V210223 –  M35M1_V250922
TIMELINE
  Sep 10  Reserved by VulnCheck
  Sep 11  Published (CNA: VulnCheck)
  Sep 15  EXPLOIT PUBLISHED — CVE-2026-89009 (WAVLINK Technology WN535M1). Public exploit reference added.
CWE-36 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Deferred

Description

WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated arbitrary file write vulnerability that allows remote attackers to overwrite any file on the device by sending a crafted payload to the sync_server daemon on TCP port 13136. The daemon, which runs as root and requires no authentication, accepts a 100-byte filename field in its protocol header without path canonicalization, allowing attackers to supply an absolute path and write arbitrary content to overwrite startup scripts or credential stores to achieve persistent system compromise.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
September 10, 2026ReservedReserved by VulnCheck
September 11, 2026PublishedPublished (CNA: VulnCheck)
September 15, 2026EXPLOIT PUBLISHEDEXPLOIT PUBLISHED — CVE-2026-89009 (WAVLINK Technology WN535M1). Public exploit reference added.

Affected

Affected products and packages — 2 rows
VendorProduct / PackageEcosystemVersion introducedFixed
WAVLINK TechnologyWN535M1—M35M1_V210223M35M1_V250922
WAVLINK TechnologyWN535M3—M35M1_V210223M35M1_V250922

Weaknesses

CWE-36

References (3)

Related

Authoritative record: CVE-2026-89009 at cve.org

Vendors: wavlink technology

Weaknesses: CWE-36

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-89009 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.