Description
A security flaw has been discovered in Wavlink WL-WN579A3 up to 20210219. Affected by this issue is the function DeleteMac of the file /cgi-bin/wireless.cgi. The manipulation of the argument delete_list results in command injection. The attack can be executed remotely. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-02-16
Score: 5.3 Medium
EPSS: 8.2% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability lies in the DeleteMac function of the wireless.cgi script on Wavlink WL‑WN579A3 routers. A specially crafted delete_list parameter allows an attacker to inject arbitrary shell commands, resulting in full control over the device. This enables the compromise of confidentiality, integrity, and availability of the router and any network traffic it handles. The flaw is categorized as command injection (CWE‑74) and improper control of remote command execution (CWE‑77).

Affected Systems

Only Wavlink WL‑WN579A3 routers with firmware versions up to 20210219 are affected. The issue is tied to the wireless.cgi file in those firmware releases; no other Wavlink models or firmware revisions are known to be impacted.

Risk and Exploitability

The CVSS base score of 5.3 indicates moderate severity, while an EPSS score of 8% suggests a relatively high likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog, implying no large‑scale attacks have been documented. Exploitation requires remote access to the router’s web interface and submission of a crafted HTTP request to /cgi-bin/wireless.cgi. The description does not specify whether authentication is required, so the exact preconditions for the attack remain unclear.

Generated by OpenCVE AI on July 31, 2026 at 18:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply an official firmware update that removes or sanitizes the DeleteMac function; if no update is available, upgrade to a newer firmware revision that does not expose the vulnerable script.
  • If an update is not feasible, disable the router’s web management interface or block remote HTTP access to /cgi-bin/wireless.cgi using the device’s firewall or a network firewall enclosure.
  • Configure monitoring to detect abnormal POST requests to /cgi-bin/wireless.cgi and alert administrators to potential exploitation attempts.

Generated by OpenCVE AI on July 31, 2026 at 18:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 18 Feb 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Wavlink wl-wn579a3 Firmware
CPEs cpe:2.3:h:wavlink:wl-wn579a3:-:*:*:*:*:*:*:*
cpe:2.3:o:wavlink:wl-wn579a3_firmware:*:*:*:*:*:*:*:*
Vendors & Products Wavlink wl-wn579a3 Firmware

Tue, 17 Feb 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 16 Feb 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Wavlink
Wavlink wl-wn579a3
Vendors & Products Wavlink
Wavlink wl-wn579a3

Mon, 16 Feb 2026 02:15:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in Wavlink WL-WN579A3 up to 20210219. Affected by this issue is the function DeleteMac of the file /cgi-bin/wireless.cgi. The manipulation of the argument delete_list results in command injection. The attack can be executed remotely. The vendor was contacted early about this disclosure but did not respond in any way.
Title Wavlink WL-WN579A3 wireless.cgi DeleteMac command injection
Weaknesses CWE-74
CWE-77
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:ND/RL:ND/RC:C'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:C'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Wavlink Wl-wn579a3 Wl-wn579a3 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-02-23T10:04:14.698Z

Reserved: 2026-02-15T09:01:34.854Z

Link: CVE-2026-2529

cve-icon Vulnrichment

Updated: 2026-02-17T17:13:56.809Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-16T02:16:07.000

Modified: 2026-06-17T10:31:15.047

Link: CVE-2026-2529

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T18:30:17Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')