Impact
The vulnerability lies in the DeleteMac function of the wireless.cgi script on Wavlink WL‑WN579A3 routers. A specially crafted delete_list parameter allows an attacker to inject arbitrary shell commands, resulting in full control over the device. This enables the compromise of confidentiality, integrity, and availability of the router and any network traffic it handles. The flaw is categorized as command injection (CWE‑74) and improper control of remote command execution (CWE‑77).
Affected Systems
Only Wavlink WL‑WN579A3 routers with firmware versions up to 20210219 are affected. The issue is tied to the wireless.cgi file in those firmware releases; no other Wavlink models or firmware revisions are known to be impacted.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate severity, while an EPSS score of 8% suggests a relatively high likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog, implying no large‑scale attacks have been documented. Exploitation requires remote access to the router’s web interface and submission of a crafted HTTP request to /cgi-bin/wireless.cgi. The description does not specify whether authentication is required, so the exact preconditions for the attack remain unclear.
OpenCVE Enrichment