PT-2026-26975 · Wavlink · Wavlink Wl-Wn578W2
Ltzhuster
+1
·
Published
2026-03-22
·
Updated
2026-03-23
·
CVE-2026-4544
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Wavlink WL-WN578W2 version 221110
Description
A cross-site scripting issue exists in the POST Request Handler component of Wavlink WL-WN578W2. The issue is related to the manipulation of the
homepage/hostname/login page argument within a POST request to the /cgi-bin/login.cgi endpoint. This allows for remote execution of malicious scripts. The exploit has been publicly disclosed.Recommendations
Versions prior to 221110 should be updated. As a temporary workaround, consider restricting access to the
/cgi-bin/login.cgi endpoint.Exploit
Fix
Code Injection
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wavlink Wl-Wn578W2