PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-89009 WAVLINK Technology CVE debrief

CVE-2026-89009 is a high-severity vulnerability affecting WAVLINK WN535M1 and WN535M3 routers with firmware prior to M35M1_V250922. The vulnerability allows unauthenticated attackers to write arbitrary files on the device, potentially leading to persistent system compromise. This could result from overwriting startup scripts or credential stores. Defenders should assess exposure and prioritize remediation efforts based on the CVSS score of 8.8 and the potential for significant operational impact.

Vendor
WAVLINK Technology
Product
WN535M1
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-11
Original CVE updated
2026-09-11
Advisory published
2026-09-11
Advisory updated
2026-09-11

Who should care

Defenders responsible for WAVLINK WN535M1 and WN535M3 routers, network administrators, and security teams should assess exposure and prioritize remediation. This includes reviewing current configurations, verifying firmware versions, and implementing compensating controls where necessary. The vulnerability's high CVSS score and potential for significant operational impact necessitate prompt attention from these stakeholders.

Why it matters

CVE-2026-89009 is a high-severity vulnerability that allows unauthenticated attackers to write arbitrary files on WAVLINK WN535M1 and WN535M3 routers. Defenders should assess exposure, prioritize remediation, and monitor for potential exploitation attempts.

  • Potential persistent system compromise through overwriting of startup scripts or credential stores
  • Possible disruption of critical network services
  • Potential data tampering or unauthorized access
  • Verification of firmware versions and configuration files

Technical summary

The WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 are vulnerable to an unauthenticated arbitrary file write vulnerability. This allows remote attackers to overwrite any file on the device by sending a crafted payload to the sync_server daemon on TCP port 13136. The daemon runs as root and requires no authentication, exacerbating the vulnerability's severity. The vulnerability's impact includes potential persistent system compromise through overwriting of startup scripts or credential stores.

Defensive priority

High priority for immediate assessment and remediation

Recommended defensive actions

  • Assess exposure of WAVLINK WN535M1 and WN535M3 routers in your environment
  • Verify firmware versions and apply updates if available
  • Monitor network traffic to detect potential exploitation attempts
  • Implement compensating controls to restrict access to affected devices
  • Review and update incident response plans to address potential exploitation
  • Conduct a thorough risk assessment to identify potential targets for exploitation
  • Engage with the vendor for additional guidance or support if needed

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including its description, CVSS score, and affected products. However, the vendor and product information is not fully confirmed. The vulnerability is caused by the sync_server daemon accepting a 100-byte filename field without path canonicalization, allowing for arbitrary file writes. The CVE Program and NVD entries serve as primary sources for this information.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-89009 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-89009

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-89009 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-89009

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.