CVE report

CVE-2020-13117critical

Wavlink Multiple AP - Remote Command Injection

Events 90d

10,657

Distinct IPs

286

Severity

critical

CISA KEV

Not listed

Detection signature

An event counts toward CVE-2020-13117 when its URL path contains any of these (case-insensitive). This is what our matching is based on.

  • ยท /cgi-bin/login.cgi

Pre-disclosure activity

all early actors โ†’

Analysing probe history around the publication dateโ€ฆ

Recent probe volume (last 7 days)

peak: 342 events/day
04-2805-1505-2806-1006-2307-0607-1907-27
eventsdistinct IPs

Downloads & integrations

Top sources probing for CVE-2020-13117

Top networks the attempts come from

Fingerprints of the clients exploiting this

The HTTP (JA4H) and TLS (JA4) fingerprints seen on these attempts. Click one to see the whole population that carries it.

Sample request paths observed

  • /cgi-bin/login.cgi