Wavlink WL-WN579A3 Command Injection Vulnerability in Wireless Configuration CGI
Vulnerability
A command injection vulnerability has been identified in the Wavlink WL-WN579A3 router, specifically in versions prior to 20210219. The issue arises in the 'AddMac' function within the '/cgi-bin/wireless.cgi' file, where the 'macAddr' parameter can be manipulated to execute arbitrary commands. This vulnerability can be exploited remotely, and a public proof-of-concept exploit is available.
Impact
Exploitation of this vulnerability allows for arbitrary command execution on the device.
Reproduction
The vulnerability can be reproduced by sending a POST request to '/cgi-bin/wireless.cgi' with the 'page' parameter set to 'AddMac' and the 'macAddr' parameter containing the payload for command execution. The request must be made with a valid session cookie.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
