CVE-2026-3715: Wavlink WL-WN579X3-C firewall.cgi sub_40139C stack-based overflow
A vulnerability was found in Wavlink WL-WN579X3-C 231124. This affects the function sub40139C of the file /cgi-bin/firewall.cgi. Performing a manipulation of the argument delflag results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been made public and could be used. Upgrading to version 20260226 is able to mitigate this issue. You should upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3715?
CVE-2026-3715 is classified as a high-severity vulnerability due to the potential for stack-based buffer overflow, which could lead to arbitrary code execution.
How do I fix CVE-2026-3715?
To fix CVE-2026-3715, update the Wavlink WL-WN579X3-C firmware to the latest version that addresses this vulnerability.
What products are affected by CVE-2026-3715?
CVE-2026-3715 affects the Wavlink WL-WN579X3-C with firmware version 231124.
What type of vulnerability is CVE-2026-3715?
CVE-2026-3715 is a stack-based buffer overflow vulnerability that can be exploited through the firewall.cgi script.
What can an attacker achieve by exploiting CVE-2026-3715?
An attacker exploiting CVE-2026-3715 could potentially execute arbitrary code on the affected device, compromising its security.