Impact
A flaw in the /cgi-bin/login.cgi script of the Wavlink WL‑WN579A3 router allows an attacker to inject shell commands by manipulating the "key" parameter. This injection gives the attacker the ability to execute arbitrary commands on the router’s operating system, potentially enabling unauthorized configuration changes, traffic interception, or other disruptive actions. The vulnerability is identified as CWE‑74 and CWE‑77.
Affected Systems
The vulnerability affects Wavlink WL‑WN579A3 routers with firmware versions up to and including 20210219. It targets the /cgi-bin/login.cgi endpoint of the device, which is accessible over the network and therefore potentially reachable from external networks.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, while the EPSS score of 8% reflects a moderate likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, but it has been publicly disclosed and can be leveraged remotely via crafted HTTP requests to the login CGI endpoint. The risk remains until a fixed firmware release becomes available or mitigated by network controls.
OpenCVE Enrichment