SEE MATPROOF ON YOUR STACK — BOOK A 30-MINUTE DEMO
CVEnvd11 Sept 2026

CVE-2026-89009 (CVSS 9.1) — WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated arbitrary file write vulnerability that allows remote attackers to overwrite any file on the devi

CVE. Sourced from nvd, summarised by Matproof.

AI Analysis

What changed and what to do.

The National Vulnerability Database has published CVE-2026-89009, a critical vulnerability (CVSS 9.1) affecting WAVLINK WN535M1 and WN535M3 routers running firmware versions prior to M35M1_V250922. The flaw is an unauthenticated arbitrary file write, meaning a remote attacker can overwrite any file on the device without logging in. This could allow full compromise, persistent backdoors, or disruption of network traffic.

Any organization using these router models is affected, particularly small businesses, branch offices, retail sites, and remote or home offices where consumer-grade WAVLINK equipment is deployed. Because the vulnerability is remotely exploitable without credentials, exposure is high wherever these devices are internet-facing or on untrusted networks.

Compliance teams should immediately inventory their environments to identify affected devices and confirm firmware versions. Where the patched firmware M35M1_V250922 or later is available, prioritize updating. If patching is not possible, isolate or replace the devices and restrict remote access. Document the remediation steps and timelines for audit purposes, and review third-party or vendor risk registers to confirm whether these routers appear in supplier or managed service environments.

This summary is AI-generated for orientation purposes. For regulatory action, always consult the original source linked above.

More CVE updates

Latest in CVE.

Live regulatory monitoring

Never miss a compliance update.

Get weekly digests of DORA, NIS2, GDPR, MaRisk, and ISO 27001 changes — straight to your inbox. Free.

No spam. Weekly digest only. Unsubscribe anytime.

DORANIS2GDPRMaRiskISO 27001

Map this to your controls

Connect regulatory changes to your compliance work.

Matproof maps every regulator update directly to your controls and surfaces the ones that affect your organisation — across 21 frameworks.

CVE-2026-89009 (CVSS 9.1) — WAVLINK WN535M1 and WN535M3 r… — CVE | Matproof