CVE-2025-10324: Wavlink WL-WN578W2 firewall.cgi sub_401C5C command injection
A vulnerability was determined in Wavlink WL-WN578W2 221110. This affects the function sub401C5C of the file firewall.cgi. This manipulation of the argument pingFrmWANFilterEnabled/blockSynFloodEnabled/blockPortScanEnabled/remoteManagementEnabled causes command injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10324?
The severity of CVE-2025-10324 is high due to the potential for command injection.
How do I fix CVE-2025-10324?
To fix CVE-2025-10324, update the firmware of Wavlink WL-WN578W2 to the latest version provided by the manufacturer.
What systems are affected by CVE-2025-10324?
CVE-2025-10324 affects the Wavlink WL-WN578W2 model router.
What type of vulnerability is CVE-2025-10324?
CVE-2025-10324 is a command injection vulnerability.
Can CVE-2025-10324 lead to data breaches?
Yes, CVE-2025-10324 can potentially lead to unauthorized access and data breaches if exploited.