Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-89009
WAVLINK WN535M1/WN535M3 Unauthenticated Arbitrary File Write via sync_server
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N N H H 8.8 .0101 61.9 —
AFFECTED
Product Versions Fixed
WN535M1 M35M1_V210223 – M35M1_V250922
WN535M3 M35M1_V210223 – M35M1_V250922
TIMELINE
Sep 10 Reserved by VulnCheck
Sep 11 Published (CNA: VulnCheck)
Sep 15 EXPLOIT PUBLISHED — CVE-2026-89009 (WAVLINK Technology WN535M1). Public exploit reference added.
Description
WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated arbitrary file write vulnerability that allows remote attackers to overwrite any file on the device by sending a crafted payload to the sync_server daemon on TCP port 13136. The daemon, which runs as root and requires no authentication, accepts a 100-byte filename field in its protocol header without path canonicalization, allowing attackers to supply an absolute path and write arbitrary content to overwrite startup scripts or credential stores to achieve persistent system compromise.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| September 10, 2026 | Reserved | Reserved by VulnCheck |
| September 11, 2026 | Published | Published (CNA: VulnCheck) |
| September 15, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-89009 (WAVLINK Technology WN535M1). Public exploit reference added. |
Affected
Affected products and packages — 2 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| WAVLINK Technology | WN535M1 | — | M35M1_V210223 | M35M1_V250922 |
| WAVLINK Technology | WN535M3 | — | M35M1_V210223 | M35M1_V250922 |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-89009 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.