CVE-2026-2529: Wavlink Wl-WN579A3 Firmware

Critical severity, CVSS 9.8. EPSS: 8.7% chance of exploitation in the next 30 days.

A security flaw has been discovered in Wavlink WL-WN579A3 up to 20210219. Affected by this issue is the function DeleteMac of the file /cgi-bin/wireless.cgi. The manipulation of the argument delete_list results in command injection. The attack can be executed remotely. The vendor was contacted early about this disclosure but did not respond in any way.

Affected products

  • Wavlink Wl-WN579A3 Firmware: up to and including 2021-02-19

Published 2026-02-16. Last modified 2026-06-17.