A vulnerability was found in Wavlink WL-WN579X3-C 231124. This affects the function sub_40139C of the file /cgi-bin/firewall.cgi. Performing a manipulation of the argument del_flag results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been made public and could be used. Upgrading to version 20260226 is able to mitigate this issue. You should upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
References
| Link | Resource |
|---|---|
| https://dl.wavlink.com/firmware/RD/WN579X3C_WAVLINK_V20260226_WO_cb3003b2.bin | Broken Link |
| https://github.com/Litengzheng/vul_db/blob/main/WL-WN579X3-C/vul_17/README.md | Exploit Third Party Advisory |
| https://vuldb.com/?ctiid.349660 | Permissions Required VDB Entry |
| https://vuldb.com/?id.349660 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.765325 | Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
| AND |
|
History
10 Mar 2026, 18:55
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:o:wavlink:wl-wn579x3-c_firmware:231124:*:*:*:*:*:*:* cpe:2.3:h:wavlink:wl-wn579x3-c:-:*:*:*:*:*:*:* |
|
| References | () https://dl.wavlink.com/firmware/RD/WN579X3C_WAVLINK_V20260226_WO_cb3003b2.bin - Broken Link | |
| References | () https://github.com/Litengzheng/vul_db/blob/main/WL-WN579X3-C/vul_17/README.md - Exploit, Third Party Advisory | |
| References | () https://vuldb.com/?ctiid.349660 - Permissions Required, VDB Entry | |
| References | () https://vuldb.com/?id.349660 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/?submit.765325 - Third Party Advisory, VDB Entry | |
| First Time |
Wavlink wl-wn579x3-c Firmware
Wavlink wl-wn579x3-c Wavlink |
|
| Summary |
|
08 Mar 2026, 07:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-08 07:16
Updated : 2026-03-10 18:55
NVD link : CVE-2026-3715
Mitre link : CVE-2026-3715
CVE.ORG link : CVE-2026-3715
JSON object : View
Products Affected
wavlink
- wl-wn579x3-c_firmware
- wl-wn579x3-c
