PT-2026-33617 · Wavlink · Wl-Wn579A3

Ltzhust2

·

Published

2026-04-19

·

Updated

2026-04-19

·

CVE-2026-6559

CVSS v2.0

5.0

Medium

AV:N/AC:L/Au:N/C:N/I:P/A:N
A weakness has been identified in Wavlink WL-WN579A3 220323. This affects the function sub 401F80 of the file /cgi-bin/login.cgi. This manipulation of the argument Hostname causes cross site scripting. Remote exploitation of the attack is possible. Upgrading the affected component is recommended. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

Fix

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-6559

Affected Products

Wl-Wn579A3