CVE-2026-4163
CRITICAL Exploitation: PoC
9.8
CVSS 3.1
Description
A vulnerability was detected in Wavlink WL-WN579A3 220323. This issue affects the function SetName/GuestWifi of the file /cgi-bin/wireless.cgi of the component POST Request Handler. Performing a manipulation results in command injection. It is possible to initiate the attack remotely. The exploit is now public and may be used. Upgrading the affected component is recommended.
Metadata
Severity & Metrics
9.8
CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
SSVC — CISA Coordinator
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Wavlink | WL-WN579A3 | — | 220323 |
CVSS scores (4)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 10.0 | N/D | 2.0 | cna | AV:N/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:OF/RC:C |
| 9.8 | CRITICAL | 3.1 | cna | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C |
| 9.8 | CRITICAL | 3.0 | cna | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C |
| 9.3 | CRITICAL | 4.0 | cna | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P |
References (7)
- VDB-351070 | Wavlink WL-WN579A3 POST Request wireless.cgi GuestWifi command injection https://vuldb.com/?id.351070
- VDB-351070 | CTI Indicators (IOB, IOC, TTP, IOA) https://vuldb.com/?ctiid.351070
- Submit #765327 | Wavlink WL-WN579A3 V220323 Command Injection https://vuldb.com/?submit.765327
- Submit #765328 | Wavlink WL-WN579A3 V220323 Command Injection (Duplicate) https://vuldb.com/?submit.765328
- https://github.com/Litengzheng/vul_db/blob/main/WL-WN579A3/vul_9/README.md
- https://github.com/Litengzheng/vul_db/blob/main/WL-WN579A3/vul_10/README.md
- https://dl.wavlink.com/firmware/RD/WINSTAR_WN579A3-A-2026-03-10-94f93d4-WO-mt7628-squashfs-sysupgrade.bin