PT-2026-28722 · Wavlink · Wavlink Wl-Wn579X3-C

Ltzhuster2

+1

·

Published

2026-03-27

·

Updated

2026-03-29

·

CVE-2026-5004

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Wavlink WL-WN579X3-C version 231124
Description A stack-based buffer overflow exists in the UPNP Handler component of the Wavlink WL-WN579X3-C. The issue is located in the sub 4019FC function of the /cgi-bin/firewall.cgi file. Manipulation of the UpnpEnabled argument can trigger the overflow, allowing for remote attacks. The exploit has been publicly disclosed. The vendor was contacted but did not respond.
Recommendations Versions prior to 231124 should be updated. As a temporary workaround, consider disabling the UPNP functionality to minimize the risk of exploitation.

Exploit

Fix

Stack Overflow

Memory Corruption

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-5004

Affected Products

Wavlink Wl-Wn579X3-C