Impact
The vulnerability resides in the AddMac command of /cgi-bin/wireless.cgi on the Wavlink WL‑WN579A3 router. By manipulating the macAddr argument, an attacker can inject arbitrary shell commands, leading to remote execution of code on the device.
Affected Systems
The affected product is the Wavlink WL‑WN579A3 wireless router. All firmware releases up to the 20210219 are impacted.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score of 8% suggests a relatively low probability of exploitation in the wild. The flaw enables remote code execution and publicly available exploit code can be deployed. The vendor did not respond to disclosure, so no official patch exists at present, and the vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment