CVE-2026-4163Disclosure

LOWCVSS 8.9 · HIGH

Exploit discussion active in current signal (4 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A vulnerability was detected in Wavlink WL-WN579A3 220323. This issue affects the function SetName/GuestWifi of the file /cgi-bin/wireless.cgi of the component POST Request Handler. Performing a manipulation results in command injection. It is possible to initiate the attack remotely. The exploit is now public and may be used. Upgrading the affected component is recommended.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-77

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 7 signals
  • Disclosure: 3 classified signals
  • Peaked at 4 mentions on most recent observed day (2026-03-16)
  • 7 total mentions across 3 days

Deep dive

Activity timeline7 mentions / 3d
01234Mentions · 2026-03-14: 1Mentions · 2026-03-15: 2Mentions · 2026-03-16: 4PoC Mentioned / Linked · 2026-03-14: 1Patch / Workaround · 2026-03-16: 2Technical Details · 2026-03-14: 1Technical Details · 2026-03-15: 2Technical Details · 2026-03-16: 403-1403-1503-16
Signal classification4 categories
Disclosure
342.9%
Patch
228.6%
PoC
114.3%
General
114.3%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-141
PoC1
2026-03-152
Disclosure2
2026-03-164
Disclosure1General1Patch2
Full discourse7 posts
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-4163 — CVSS 9.8/10 ██████████ A vulnerability was detected in Wavlink WL-WN579A3 220323. This issue affects the function SetName/GuestWifi of the... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/ay2VACzk7b

    Post summary

    CVE-2026-4163, a critical vulnerability in Wavlink's WL‑WN579A3 device, has been confirmed with a CVSS score of 9.8/10; a vendor patch is available, though no exploit or PoC details were provided.

    1101057
    6 followersView on X
  • The Hacker Wire@TheHackerWire
    General

    🔴 CVE-2026-4163 - Critical A vulnerability was detected in Wavlink WL-WN579A3 220323. This issue affects the function SetName/GuestWifi of the file /cgi-bin/wireless.cgi of the component POST Request Handler. Perfor... https://www.thehackerwire.com/vulnerability/CVE-2026-4163/ https://t.co/wibeZ1hOKz

    Post summary

    A newly identified vulnerability (CVE-2026‑4163) targets the SetName/GuestWifi function in Wavlink routers, but no PoC, exploit, active exploitation report, or patch details are provided.

    0000048
    136 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-4163: CRITICAL] Critical vulnerability in Wavlink WL-WN579A3 220323 discovered - allows remote command injection through SetName/GuestWifi function. Upgrade advised to secure against exploit.#cve,CVE-2026-4163,#cybersecurity https://cvefind.com/CVE-2026-4163

    Post summary

    A critical remote command injection flaw (CVE-2026-4163) was discovered in the Wavlink WL‑WN579A3, and an upgrade is advised to mitigate the issue.

    0000040
    601 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4163 Remote Command Injection in Wavlink WL-WN579A3 220323 via ... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4163 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The tweet announces a newly discovered Remote Command Injection vulnerability (CVE-2026-4163) in the Wavlink WL-WN579A3, linking to a details page and a scanner alert, without providing exploitation or patch details.

    0000041
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4163 - Wavlink WL-WN579A3 POST Request wireless.cgi GuestWifi command injection Intel Report: https://ift.tt/4hjs6bL

    Post summary

    The alert reports CVE-2026-4163, a command‑injection flaw in Wavlink WL‑WN579A3 caused by a GuestWifi POST request to wireless.cgi; no exploit, patch, or active exploitation is referenced.

    0000039
    336 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4163 A vulnerability was detected in Wavlink WL-WN579A3 220323. This issue affects the function SetName/GuestWifi of the file /cgi-bin/wireless.cgi of the component POST Req… https://www.cve.org/CVERecord?id=CVE-2026-4163

    Post summary

    A new CVE (CVE-2026-4163) has been identified for Wavlink WL-WN579A3 routers, affecting the SetName/GuestWifi function in the wireless.cgi file, with no exploit, patch, or PoC details available.

    0000075
    56.7K followersView on X
  • 0day Signal@0dayPublishing
    PoC

    🚨 CVE-2026-4163: Wavlink WL-WN579A3 POST Request w... Remote command injection in Wavlink router's guest WiFi handler with public exploit and 9.3 CVSS - another IoT device be... https://zerodaysignal.com/vulnerability/CVE-2026-4163 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet discloses a severe remote command injection vulnerability in a Wavlink router (CVE-2026-4163), notes a public exploit and a high CVSS score, but offers no patch or evidence of active attacks.

    0000076
    150 followersView on X

Explore more