CVE-2026-2529: Wavlink WL-WN579A3 wireless.cgi DeleteMac command injection
A security flaw has been discovered in Wavlink WL-WN579A3 up to 20210219. Affected by this issue is the function DeleteMac of the file /cgi-bin/wireless.cgi. The manipulation of the argument deletelist results in command injection. The attack can be executed remotely. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2529?
CVE-2026-2529 is classified as a high-severity vulnerability due to its potential for command injection.
How do I fix CVE-2026-2529?
To fix CVE-2026-2529, update your Wavlink WL-WN579A3 device to the latest firmware version provided by the manufacturer.
Which versions are affected by CVE-2026-2529?
CVE-2026-2529 affects Wavlink WL-WN579A3 devices with firmware versions up to and including 20210219.
What type of vulnerability is CVE-2026-2529?
CVE-2026-2529 is a command injection vulnerability that affects the DeleteMac function in the wireless.cgi file.
Can CVE-2026-2529 be exploited remotely?
Yes, CVE-2026-2529 can be exploited remotely by manipulating parameters sent to the affected DeleteMac function.