Answer in brief
CVE-2026-89010 records a Unknown severity vulnerability in WAVLINK WN535M1/WN535M3 Unauthenticated OS Command Injection via sync_server. The current sources do not mark it as known exploited. The current feed maps WAVLINK Technology/WN535M1 (generic), WAVLINK Technology/WN535M3 (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps WAVLINK Technology/WN535M1 (generic), WAVLINK Technology/WN535M3 (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| WAVLINK Technology/WN535M1generic | M35M1_V210223 | Not reported |
| WAVLINK Technology/WN535M3generic | M35M1_V210223 | Not reported |
Published upstream
Sep 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 11, 2026
WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted filenames to the sync_server daemon on TCP port 13136. The daemon interpolates attacker-controlled filename input containing shell metacharacters into a shell command string via sprintf() and passes it to system() without sanitization, enabling root-level command execution on the device.
Quoted source text, attributed separately from HOL analysis.