CVE-2026-89009 Details
Description
WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated arbitrary file write vulnerability that allows remote attackers to overwrite any file on the device by sending a crafted payload to the sync_server daemon on TCP port 13136. The daemon, which runs as root and requires no authentication, accepts a 100-byte filename field in its protocol header without path canonicalization, allowing attackers to supply an absolute path and write arbitrary content to overwrite startup scripts or credential stores to achieve persistent system compromise.
WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 have an unauthenticated arbitrary file write vulnerability. This issue allows remote attackers to overwrite any file on the device by sending a crafted payload to the sync_server daemon on TCP port 13136. The daemon operates with root privileges and requires no authentication. It accepts a 100-byte filename field in its protocol header without proper path validation, enabling attackers to specify absolute paths and write arbitrary content. This vulnerability can be exploited to overwrite startup scripts or credential stores, leading to persistent system compromise.
Users can upgrade to the M35M1_V250922 firmware version, although this requires a two-step U-Boot Recovery procedure due to the risk of bricking the device. Alternatively, the sync_server can be disabled by setting MeshMode to 0, which stops the service from listening on TCP 13136.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 11, 2026CISA-ADP
Assessed Sep 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/camdsmith/wavlink-sync_server-rce/blob/main/README.md | CISA-ADP | ExploitTechnical Analysis |
| https://docs.wavlink.xyz/ | [email protected] | Vendor |
| https://github.com/camdsmith/wavlink-sync_server-rce/blob/main/README.md | [email protected] | ExploitTechnical Analysis |
| https://www.vulncheck.com/advisories/wavlink-wn535m1-wn535m3-unauthenticated-arbitrary-file-write-via-sync-server | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-36 | Absolute Path Traversal | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| WAVLINK WN535M1 | <= M35M1_V210223 |
CPE
Remediation
| |
| WAVLINK WN535M3 | <= M35M1_V210223 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 15, 2026 | CVE Modified | CISA-ADP |
| Sep 11, 2026 | New CVE Received | [email protected] |
Volerion