CVE-2018-5789: Extremewireless Wing

High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.

An issue was discovered in Extreme Networks ExtremeWireless WiNG 5.x before 5.8.6.9 and 5.9.x before 5.9.1.3. There is a Remote, Unauthenticated XML Entity Expansion Denial of Service on the WiNG Access Point / Controller via crafted XML entities to the Web User Interface.

Affected products

  • Extremewireless Wing: from 5.0, before 5.8.6.9 (fixed in 5.8.6.9); from 5.9.0, before 5.9.1.3 (fixed in 5.9.1.3)

Published 2018-02-05. Last modified 2026-06-17.