CVE-2026-2529Disclosure(wavlink / wl-wn579a3)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A security flaw has been discovered in Wavlink WL-WN579A3 up to 20210219. Affected by this issue is the function DeleteMac of the file /cgi-bin/wireless.cgi. The manipulation of the argument delete_list results in command injection. The attack can be executed remotely. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-77

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wl-wn579a3
  • wl-wn579a3_firmware

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-02-16); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
wl-wn579a3wl-wn579a3_firmware

1 version affected across 2 products

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-16: 2Mentions · 2026-02-18: 1Technical Details · 2026-02-16: 1Technical Details · 2026-02-18: 102-1602-18
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-162
Disclosure1General1
2026-02-181
Disclosure1
Full discourse3 posts
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-2529 📊 Severity: 6.3 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-2529 #CVE-2026-2529 #CVE #Medium #CyberSecurity #InfoSec https://t.co/dtzxYpQApE

    Post summary

    A new medium‑severity CVE (2026‑2529) affecting unspecified products has been reported, with basic details available on NVD.

    0001041
    56 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-2529 Command Injection Vulnerability in Wavlink WL-WN579A3 Wireless Router https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-2529

    Post summary

    The text cites CVE‑2026‑2529 as a command injection flaw in a Wavlink router, but provides no additional details, exploit evidence, or mitigation information.

    0001049
    4.0K followersView on X
  • Cybersecurity Aide@SecAideInfo
    Disclosure

    🚨⚠️ Heads up! CVE-2026-2529 alert 🚨 Critical flaw in Wavlink WL-WN579A3 (up to 20210219) allows remote command injection via DeleteMac in /cgi-bin/wireless.cgi 📡🚫. Vendor unresponsive. Be proactive & secure your devices ASAP! 🔒🛡️ #CyberSecurity #VulnerabilityAlert

    Post summary

    The post alerts readers to CVE-2026-2529, a remote command injection flaw affecting Wavlink WL-WN579A3, but offers no evidence of active exploitation, a PoC, or a patch.

    0000028
    20 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWwavlinkwl-wn579a3---
OSwavlinkwl-wn579a3_firmware---

Explore more