CVE-2026-4164: Wavlink WL-WN578W2 POST Request wireless.cgi GuestWifi command injection
A flaw has been found in Wavlink WL-WN578W2 221110. Impacted is the function DeleteMaclist/SetName/GuestWifi of the file /cgi-bin/wireless.cgi of the component POST Request Handler. Executing a manipulation can lead to command injection. It is possible to launch the attack remotely. The exploit has been published and may be used. It is recommended to upgrade the affected component.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4164?
CVE-2026-4164 has been classified with a high severity due to its potential for command injection vulnerabilities.
How do I fix CVE-2026-4164?
To mitigate CVE-2026-4164, users should update their Wavlink WL-WN578W2 device firmware to the latest version provided by the vendor.
What systems are affected by CVE-2026-4164?
CVE-2026-4164 affects the Wavlink WL-WN578W2 wireless router running the specified firmware version.
What kind of attacks can be executed due to CVE-2026-4164?
Exploitation of CVE-2026-4164 can allow an attacker to perform command injection via crafted POST requests.
Is there a workaround for CVE-2026-4164?
While a specific workaround might not be available, disabling the guest WiFi feature can help reduce exposure to CVE-2026-4164.