PT-2026-8301 · Wavlink · Wavlink Wl-Wn579A3

Kdb3169

·

Published

2026-02-16

·

Updated

2026-02-16

·

CVE-2026-2527

CVSS v2.0
6.5
VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Wavlink WL-WN579A3 versions up to 20210219
Description A command injection issue exists in the file
/cgi-bin/login.cgi
. Manipulating the
key
argument can allow for remote code execution. The vulnerability has been publicly disclosed. The vendor was notified but did not respond.
Recommendations Update Wavlink WL-WN579A3 to a version later than 20210219. As a temporary workaround, restrict access to the
/cgi-bin/login.cgi
file. Avoid using the
key
parameter in the
/cgi-bin/login.cgi
endpoint until the issue is resolved.

Exploit

Fix

Command Injection

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2026-2527

Affected Products

Wavlink Wl-Wn579A3