A vulnerability is in the 'wx.html' page of the WAVLINK AC1200, version WAVLINK-A42W-1.27.6-20180418, which can allow a remote attacker to access this page without any authentication. When an unauthorized user accesses this page directly, it connects to this device as a friend of the device owner.
http://192.168.1.40/wx.html
AC1200
Visiting the corresponding page directly through the mobile browser can reveal some key information about the device. Or you can get key information about the device by using the following command.
z3