CVE-2025-10359: Wavlink WL-WN578W2 wireless.cgi sub_404DBC os command injection
A vulnerability was detected in Wavlink WL-WN578W2 221110. This impacts the function sub404DBC of the file /cgi-bin/wireless.cgi. The manipulation of the argument macAddr results in os command injection. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10359?
CVE-2025-10359 has been classified as a high severity vulnerability due to its potential for remote exploitation through OS command injection.
How do I fix CVE-2025-10359?
To fix CVE-2025-10359, update the Wavlink WL-WN578W2 firmware to the latest version released by the manufacturer.
What are the potential risks of CVE-2025-10359?
The potential risks of CVE-2025-10359 include unauthorized remote command execution, which can lead to full system compromise.
Which products are affected by CVE-2025-10359?
CVE-2025-10359 specifically affects the Wavlink WL-WN578W2 device.
How can CVE-2025-10359 be exploited?
CVE-2025-10359 can be exploited remotely via manipulation of the 'macAddr' argument in the '/cgi-bin/wireless.cgi' script.