Wavlink WL-WN579A3 Command Injection Vulnerability in Wireless Configuration CGI

Vulnerability

A command injection vulnerability has been identified in the Wavlink WL-WN579A3 router, specifically in versions prior to 20210219. The issue arises in the 'AddMac' function within the '/cgi-bin/wireless.cgi' file, where the 'macAddr' parameter can be manipulated to execute arbitrary commands. This vulnerability can be exploited remotely, and a public proof-of-concept exploit is available.

Impact

Exploitation of this vulnerability allows for arbitrary command execution on the device.

Reproduction

The vulnerability can be reproduced by sending a POST request to '/cgi-bin/wireless.cgi' with the 'page' parameter set to 'AddMac' and the 'macAddr' parameter containing the payload for command execution. The request must be made with a valid session cookie.

Added: Feb 16, 2026, 4:26 AM
Updated: Feb 16, 2026, 4:26 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
8.7
remediation
0.0
relevance
3.1
threat
6.4
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.