CVE-2026-6483: Wavlink WL-WN530H4 internet.cgi snprintf os command injection
A vulnerability was found in Wavlink WL-WN530H4 20220721. This vulnerability affects the function strcat/snprintf of the file /cgi-bin/internet.cgi. The manipulation results in os command injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. Upgrading to version 2026.04.16 is able to resolve this issue. Upgrading the affected component is recommended.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Wavlink WL-WN530H4 (internet.cgi)to a version that resolves this vulnerability.Fixed in 2026.04.16
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6483?
CVE-2026-6483 is considered a critical vulnerability due to its potential for remote code execution through OS command injection.
How do I fix CVE-2026-6483?
To fix CVE-2026-6483, you should update the Wavlink WL-WN530H4 to the latest firmware version provided by the vendor.
What systems are affected by CVE-2026-6483?
CVE-2026-6483 specifically affects the Wavlink WL-WN530H4 device running firmware version 20220721.
What type of vulnerability is CVE-2026-6483?
CVE-2026-6483 is categorized as an OS command injection vulnerability.
Can CVE-2026-6483 be exploited remotely?
Yes, CVE-2026-6483 can be exploited remotely, allowing an attacker to execute arbitrary commands on the affected device.