CVE-2026-4164Disclosure

HIGHCVSS 8.9 · HIGH

Exploitation ongoing with high activity in latest observed window (4 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A flaw has been found in Wavlink WL-WN578W2 221110. Impacted is the function Delete_Mac_list/SetName/GuestWifi of the file /cgi-bin/wireless.cgi of the component POST Request Handler. Executing a manipulation can lead to command injection. It is possible to launch the attack remotely. The exploit has been published and may be used. It is recommended to upgrade the affected component.

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-77

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 8 mentions across 2 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 8 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 4 mentions (2026-03-15); latest day: 4
  • 8 total mentions across 2 days

Deep dive

Activity timeline8 mentions / 2d
01234Mentions · 2026-03-15: 4Mentions · 2026-03-16: 4PoC Mentioned / Linked · 2026-03-15: 1Exploit Tool / Code · 2026-03-15: 1Active Exploitation · 2026-03-15: 1Patch / Workaround · 2026-03-16: 1Technical Details · 2026-03-15: 4Technical Details · 2026-03-16: 403-1503-16
Signal classification4 categories
Disclosure
562.5%
Exploit
112.5%
General
112.5%
Patch
112.5%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-154
Disclosure2Exploit1General1
2026-03-164
Disclosure3Patch1
Full discourse8 posts
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-4164 — CVSS 9.8/10 ██████████ A flaw has been found in Wavlink WL-WN578W2 221110. Impacted is the function Delete_Mac_list/SetName/GuestWifi of the... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/6KJYQYUJhR

    Post summary

    A CVE-2026-4164 critical flaw was reported in the Wavlink WL-WN578W2 device, affecting several functions; a patch is now available.

    1000017
    6 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-4164 - Critical A flaw has been found in Wavlink WL-WN578W2 221110. Impacted is the function Delete_Mac_list/SetName/GuestWifi of the file /cgi-bin/wireless.cgi of the component POST Request Handler. Exec... https://www.thehackerwire.com/vulnerability/CVE-2026-4164/ https://t.co/aiCWEWvhz0

    Post summary

    A critical vulnerability was disclosed in the Wavlink WL‑WN578W2 router, affecting specific CGI functions; details were published in an online article.

    0000051
    136 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-4164: CRITICAL] Critical cyber security alert: Flaw discovered in Wavlink WL-WN578W2 device, allowing remote command injections via manipulation of certain functions in the wireless configuration fil...#cve,CVE-2026-4164,#cybersecurity https://cvefind.com/CVE-2026-4164

    Post summary

    The notice announces a critical remote command injection flaw (CVE-2026-4164) found in the Wavlink WL-WN578W2 device, describing how manipulation of certain configuration functions can enable command execution. No proofs of concept, exploit code, or patches are provided.

    0000036
    601 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4164 Command Injection in Wavlink WL-WN578W2 221110 via Crafted POST Request https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4164

    Post summary

    A command injection vulnerability (CVE‑2026‑4164) was disclosed for the Wavlink WL‑WN578W2 firmware 221110, with technical details available on Vulmon but no PoC, exploit code, patch, or evidence of active exploitation.

    0000047
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4164 A flaw has been found in Wavlink WL-WN578W2 221110. Impacted is the function Delete_Mac_list/SetName/GuestWifi of the file /cgi-bin/wireless.cgi of the component POST R… https://www.cve.org/CVERecord?id=CVE-2026-4164

    Post summary

    Flaw discovered in a Wavlink router affecting specific CGI functions; no PoC, exploit, patch, or active exploitation details provided.

    00000119
    56.7K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4164 - Wavlink WL-WN578W2 POST Request wireless.cgi GuestWifi command injection Intel Report: https://ift.tt/l2aIBuT

    Post summary

    The alert announces CVE-2026-4164 as a command‑injection flaw in Wavlink WL‑WN578W2’s wireless.cgi, providing an Intel report link but no PoC, exploit, patch, or evidence of active exploitation.

    0000034
    336 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4164 - Wavlink WL-WN578W2 POST Request wireless.cgi GuestWifi command injection Intel Report: https://ift.tt/kFm2GvI

    Post summary

    The post alerts to CVE‑2026‑4164, a command‑injection flaw in Wavlink routers, providing concise technical details but no PoC, exploit code, active‑exploitation confirmation, or patch information.

    0000039
    336 followersView on X
  • 0day Signal@0dayPublishing
    Exploit

    🚨 CVE-2026-4164: Wavlink... Unauthenticated RCE via POST to wireless.cgi with public exploit code - another router becoming a botnet node in 3...2...1 #RCE #IoTpwned #botnet. https://zerodaysignal.com/vulnerability/CVE-2026-4164 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE-2026-4164, a flaw in Wavlink routers that allows unauthenticated remote code execution via a public exploit, and reports that the vulnerability is already being used to add devices to a botnet.

    00000114
    150 followersView on X

Explore more