CVE-2026-2530Disclosure(wavlink / wl-wn579a3)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A weakness has been identified in Wavlink WL-WN579A3 up to 20210219. This affects the function AddMac of the file /cgi-bin/wireless.cgi. This manipulation of the argument macAddr causes command injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-77

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wl-wn579a3
  • wl-wn579a3_firmware

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-02-16); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
wl-wn579a3wl-wn579a3_firmware

1 version affected across 2 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-16: 1Mentions · 2026-02-18: 1Technical Details · 2026-02-18: 102-1602-18
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Cybersecurity Aide@SecAideInfo
    Disclosure

    🚨#CyberAlert: CVE-2026-2530 spotted in Wavlink WL-WN579A3 routers (up to 20210219). 🚨 Remote attackers can exploit command injection via /cgi-bin/wireless.cgi. 📡 Exploit available, and no vendor response yet! Upgrade NOW or risk exposure! 🔓 #CyberSecurity #StaySafe

    Post summary

    A new CVE-2026-2530 command injection flaw in Wavlink routers has been disclosed; while an exploit is reportedly available, no patch or detailed exploit code is shared, and vendors have not responded yet.

    0000028
    20 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-2530 📊 Severity: 6.3 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-2530 #CVE-2026-2530 #CVE #Medium #CyberSecurity #InfoSec https://t.co/eYs1VCZMEj

    Post summary

    The tweet merely announces the existence of CVE-2026-2530, cites its NVD page, and provides a severity score, with no further technical, exploit, or mitigation details.

    0000037
    56 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWwavlinkwl-wn579a3---
OSwavlinkwl-wn579a3_firmware---

Explore more