{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/wn535m1--m35m1_v250922/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:h:wavlink:wn535m1:*:*:*:*:*:*:*:*","cpe:2.3:h:wavlink:wn535m3:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-89009"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["WN535M1 (\u003c M35M1_V250922)","WN535M3 (\u003c M35M1_V250922)"],"_cs_severities":["critical"],"_cs_tags":["network-security","remote-code-execution","cve-2026-89009"],"_cs_type":"advisory","_cs_vendors":["WAVLINK"],"content_html":"\u003cp\u003eWAVLINK WN535M1 and WN535M3 routers running firmware versions prior to M35M1_V250922 contain a critical vulnerability, tracked as CVE-2026-89009, which allows for unauthenticated arbitrary file write operations. The vulnerability exists within the sync_server daemon, which listens for connections on TCP port 13136. The daemon, which operates with root privileges, fails to perform path canonicalization on the filename field provided within its custom protocol header.\u003c/p\u003e\n\u003cp\u003eBy sending a specially crafted 100-byte payload to the target device, a remote attacker can specify absolute file paths to overwrite critical system files. This enables the modification of startup scripts, configuration files, or credential stores. Successful exploitation grants an attacker persistent root-level access to the affected routing infrastructure, which can be utilized for traffic interception, credential harvesting, or as a pivot point for further lateral movement within the network. Defenders should prioritize patching and ensure that management interfaces and daemon ports are not exposed to untrusted networks.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability results in full administrative (root) control over the affected WAVLINK networking hardware. An attacker can achieve persistence, modify routing tables to intercept traffic, or extract device credentials, potentially leading to widespread compromise of the internal network segment connected to the router. As these devices are typically internet-facing edge components, the potential for mass exploitation by automated scanning is high.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the firmware on all WAVLINK WN535M1 and WN535M3 devices to version M35M1_V250922 or later to address CVE-2026-89009.\u003c/li\u003e\n\u003cli\u003eApply network-level access control to restrict access to TCP port 13136, ensuring that the sync_server daemon is not reachable from the public internet or untrusted internal zones.\u003c/li\u003e\n\u003cli\u003eMonitor network traffic for anomalous outbound connections originating from router infrastructure, which may indicate post-exploitation activity or C2 communication following a successful file overwrite.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-11T17:13:55Z","date_published":"2026-09-11T17:13:55Z","id":"https://feed.craftedsignal.io/briefs/2026-09-wavlink-rce/","summary":"WAVLINK WN535M1 and WN535M3 routers are vulnerable to unauthenticated arbitrary file writes via the sync_server daemon, enabling attackers to gain root-level persistence.","title":"Unauthenticated Arbitrary File Write in WAVLINK Routers","url":"https://feed.craftedsignal.io/briefs/2026-09-wavlink-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - WN535M1 (\u003c M35M1_V250922)","version":"https://jsonfeed.org/version/1.1"}