WAVLINK mesh routers can be hijacked with zero login needed - here's what's actually confirmed

A critical flaw lets anyone on the network overwrite files and potentially seize root on two WAVLINK router models - but only if you're running old firmware with mesh mode switched on.

A newly catalogued vulnerability, CVE-2026-89009, has landed with a critical CVSS score of 9.1, and the headline claim is alarming: unauthenticated attackers can remotely overwrite any file on a vulnerable router. The catch is that it only applies to two specific WAVLINK models, and only if they haven’t been updated.

What the bug actually does

According to the NVD entry, the flaw affects WAVLINK’s WN535M1 and WN535M3 routers - marketed as the “Halo Base Pro” - running firmware older than M35M1_V250922. NVD describes it as an unauthenticated arbitrary file write, meaning someone on the network could overwrite system files without ever logging in.

A technical write-up on GitHub from the researcher who reported it fills in more detail. It points to a daemon called sync_server, which listens on TCP port 13136 whenever the router’s mesh-networking feature is switched on - and mesh mode is enabled out of the box. The researcher says the service accepts commands with no credentials, no device pairing and no user interaction, and that exploiting it can hand an attacker full root access to the router. The vendor has reportedly confirmed the bug and the finding has been independently reproduced, per the GitHub page, with the issue first reported to WAVLINK on 3 August 2026.

Worth noting: the GitHub researcher’s writeup describes two separate bugs in sync_server, filed for CVE assignment through MITRE’s CNA-LR programme, and it isn’t stated in our sources exactly how this maps onto the single CVE-2026-89009 listing now live on NVD. The practical effect - unauthenticated compromise of the device - lines up either way, but the precise technical relationship between the two write-ups hasn’t been spelt out publicly.

So who is actually at risk

This is not a broad, install-everywhere alert. It applies specifically to WN535M1 and WN535M3 units running firmware before M35M1_V250922, and specifically when mesh mode is active - which, per the researcher, is the factory default. WAVLINK is a relatively niche brand best known for mesh extenders and travel routers rather than a market leader like a BT Hub or a Netgear Nighthawk, so the realistic pool of exposed devices is nowhere near as large as “critical, CVSS 9.1” might suggest to a casual reader. Neither the NVD listing nor the vendor documentation gives any figure for how many of these units are actually deployed, and there’s no evidence in the available sources that the bug is being actively exploited in the wild - this looks like responsible disclosure rather than an active attack campaign.

What to do about it

If you own a WN535M1 or WN535M3, the fix is straightforward: update to firmware M35M1_V250922 or later via WAVLINK’s own documentation, which covers the firmware upgrade process for its router range. If you don’t use mesh networking, disabling it removes the exposed service entirely, though updating is the safer bet regardless. Anyone unsure of their model number should check the sticker on the underside of the router rather than guess.

The takeaway

This is a genuine, vendor-confirmed flaw with a serious potential impact - root access with zero authentication is about as bad as router bugs get. But it’s narrowly scoped to two WAVLINK models on old firmware, there’s no sign yet of exploitation in the wild, and a firmware update closes it off. If you don’t own one of these two devices, there is nothing here to worry about.

Sources