PT-2025-37344 · Wavlink · Wavlink Wl-Wn578W2
N0Ps1Ed
·
Published
2025-08-28
·
Updated
2025-09-17
·
CVE-2025-10324
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Wavlink WL-WN578W2 version 221110
Description:
A vulnerability exists in the Wavlink WL-WN578W2 router. Manipulation of the arguments
pingFrmWANFilterEnabled, blockSynFloodEnabled, blockPortScanEnabled, or remoteManagementEnabled within the firewall.cgi file and the sub 401C5C function can lead to command injection. This manipulation is possible remotely. The exploit has been publicly disclosed.Recommendations:
As a temporary workaround, consider restricting access to the
firewall.cgi file to minimize the risk of exploitation.
Disable the pingFrmWANFilterEnabled, blockSynFloodEnabled, blockPortScanEnabled, and remoteManagementEnabled arguments.Exploit
Fix
Special Elements Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wavlink Wl-Wn578W2