CVE-2026-4163 CRITICAL

CVE-2026-4163: Wavlink WL-WN579A3 POST Request wireless.cgi GuestWifi command injection

Vendor Wavlink
Product WL-WN579A3
Weakness CWE-77
Published March 14, 2026
Last update March 17, 2026

CVSS base score

9.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P

What the vulnerability does

01Description

A vulnerability was detected in Wavlink WL-WN579A3 220323. This issue affects the function SetName/GuestWifi of the file /cgi-bin/wireless.cgi of the component POST Request Handler. Performing a manipulation results in command injection. It is possible to initiate the attack remotely. The exploit is now public and may be used. Upgrading the affected component is recommended.

Key dates

02Disclosure timeline

March 14, 2026 CVE published
March 17, 2026 Record updated