CVE-2025-44882: Command Injection
Published May 20, 2025
·Updated
A command injection vulnerability in the component /cgi-bin/firewall.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commands via a crafted input.
Affected Software
3 affected components
Wavlink WL-WN579A3
All of the following
Wavlink Wl-wn579a3 Firmware=1.0
Wavlink WL-WN579A3
Event History
May 20, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-44882?
CVE-2025-44882 is classified as a high severity command injection vulnerability.
2
How do I fix CVE-2025-44882?
To fix CVE-2025-44882, update the Wavlink WL-WN579A3 device to the latest firmware version provided by the manufacturer.
3
What can attackers do with CVE-2025-44882?
Attackers can execute arbitrary commands on the Wavlink WL-WN579A3 device via crafted input to the firewall.cgi component.
4
Is CVE-2025-44882 exploitable remotely?
Yes, CVE-2025-44882 can be exploited remotely if the vulnerable Wavlink WL-WN579A3 device is accessible over the internet.
5
How can I detect if my Wavlink WL-WN579A3 is vulnerable to CVE-2025-44882?
You can detect CVE-2025-44882 vulnerability by testing for improper input validation in the /cgi-bin/firewall.cgi component.