CVE-2026-6559

A weakness has been identified in Wavlink WL-WN579A3 220323. This affects the function sub_401F80 of the file /cgi-bin/login.cgi. This manipulation of the argument Hostname causes cross site scripting. Remote exploitation of the attack is possible. Upgrading the affected component is recommended. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Configurations

No configuration.

History

19 Apr 2026, 06:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-19 06:16

Updated : 2026-04-22 20:22


NVD link : CVE-2026-6559

Mitre link : CVE-2026-6559

CVE.ORG link : CVE-2026-6559


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-94

Improper Control of Generation of Code ('Code Injection')