<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>WN535M1 (&lt; M35M1_V250922) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/wn535m1--m35m1_v250922/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 11 Sep 2026 17:13:55 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/wn535m1--m35m1_v250922/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Unauthenticated Arbitrary File Write in WAVLINK Routers</title><link>https://feed.craftedsignal.io/briefs/2026-09-wavlink-rce/</link><pubDate>Fri, 11 Sep 2026 17:13:55 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-wavlink-rce/</guid><description>WAVLINK WN535M1 and WN535M3 routers are vulnerable to unauthenticated arbitrary file writes via the sync_server daemon, enabling attackers to gain root-level persistence.</description><content:encoded><![CDATA[<p>WAVLINK WN535M1 and WN535M3 routers running firmware versions prior to M35M1_V250922 contain a critical vulnerability, tracked as CVE-2026-89009, which allows for unauthenticated arbitrary file write operations. The vulnerability exists within the sync_server daemon, which listens for connections on TCP port 13136. The daemon, which operates with root privileges, fails to perform path canonicalization on the filename field provided within its custom protocol header.</p>
<p>By sending a specially crafted 100-byte payload to the target device, a remote attacker can specify absolute file paths to overwrite critical system files. This enables the modification of startup scripts, configuration files, or credential stores. Successful exploitation grants an attacker persistent root-level access to the affected routing infrastructure, which can be utilized for traffic interception, credential harvesting, or as a pivot point for further lateral movement within the network. Defenders should prioritize patching and ensure that management interfaces and daemon ports are not exposed to untrusted networks.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability results in full administrative (root) control over the affected WAVLINK networking hardware. An attacker can achieve persistence, modify routing tables to intercept traffic, or extract device credentials, potentially leading to widespread compromise of the internal network segment connected to the router. As these devices are typically internet-facing edge components, the potential for mass exploitation by automated scanning is high.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade the firmware on all WAVLINK WN535M1 and WN535M3 devices to version M35M1_V250922 or later to address CVE-2026-89009.</li>
<li>Apply network-level access control to restrict access to TCP port 13136, ensuring that the sync_server daemon is not reachable from the public internet or untrusted internal zones.</li>
<li>Monitor network traffic for anomalous outbound connections originating from router infrastructure, which may indicate post-exploitation activity or C2 communication following a successful file overwrite.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>network-security</category><category>remote-code-execution</category><category>cve-2026-89009</category></item></channel></rss>