Impact
A vulnerability in the /cgi-bin/login.cgi function of the Wavlink WL‑WN579A3 router allows a remote attacker to execute arbitrary shell commands by manipulating the "key" argument. This command‑injection flaw is classified as CWE‑74 and CWE‑77. If exploited, the attacker gains privileged control over the device, with the ability to modify configurations, intercept traffic, or pivot to other network assets.
Affected Systems
The flaw impacts the Wavlink WL‑WN579A3 router, specifically firmware versions up to and including 20210219. The device is a consumer‑grade router commonly deployed in home or small business environments where it may be exposed to the Internet.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score of 5% suggests a moderate probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires remote network connectivity to the router and the ability to send a crafted HTTP request to the login CGI endpoint; no specific defense‑in‑depth controls are mentioned, so once the target is reachable the attack path is straightforward. At this time no publicly available patch or firmware update that addresses the issue has been released; the vendor has been notified but has not responded with remediation information.
OpenCVE Enrichment