CVE-2026-2529

Severity CVSS v4.0:
MEDIUM
Type:
CWE-74 Injection
Publication date:
16/02/2026
Last modified:
16/02/2026

Description

A security flaw has been discovered in Wavlink WL-WN579A3 up to 20210219. Affected by this issue is the function DeleteMac of the file /cgi-bin/wireless.cgi. The manipulation of the argument delete_list results in command injection. The attack can be executed remotely. The vendor was contacted early about this disclosure but did not respond in any way.