CVE-2026-4163

A vulnerability was detected in Wavlink WL-WN579A3 220323. This issue affects the function SetName/GuestWifi of the file /cgi-bin/wireless.cgi of the component POST Request Handler. Performing a manipulation results in command injection. It is possible to initiate the attack remotely. The exploit is now public and may be used. Upgrading the affected component is recommended.
Configurations

No configuration.

History

22 Apr 2026, 21:30

Type Values Removed Values Added
Summary
  • (es) Se detectó una vulnerabilidad en Wavlink WL-WN579A3 220323. Este problema afecta la función SetName/GuestWifi del archivo /cgi-bin/wireless.cgi del componente Gestor de Solicitudes POST. Realizar una manipulación resulta en inyección de comandos. Es posible iniciar el ataque de forma remota. El exploit ahora es público y puede ser utilizado. Se recomienda actualizar el componente afectado.

16 Mar 2026, 14:19

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-16 14:19

Updated : 2026-04-22 21:30


NVD link : CVE-2026-4163

Mitre link : CVE-2026-4163

CVE.ORG link : CVE-2026-4163


JSON object : View

Products Affected

No product.

CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')