CVE-2026-2529: Wavlink Wl-WN579A3 Firmware
Critical severity, CVSS 9.8. EPSS: 8.7% chance of exploitation in the next 30 days.
A security flaw has been discovered in Wavlink WL-WN579A3 up to 20210219. Affected by this issue is the function DeleteMac of the file /cgi-bin/wireless.cgi. The manipulation of the argument delete_list results in command injection. The attack can be executed remotely. The vendor was contacted early about this disclosure but did not respond in any way.
Affected products
- Wavlink Wl-WN579A3 Firmware: up to and including 2021-02-19
Published 2026-02-16. Last modified 2026-06-17.