CVE-2026-4544Disclosure(wavlink / wl-wn578w2)

LOWCVSS 4.8 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was determined in Wavlink WL-WN578W2 221110. This affects an unknown function of the file /cgi-bin/login.cgi of the component POST Request Handler. Executing a manipulation of the argument homepage/hostname/login_page can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wl-wn578w2
  • wl-wn578w2_firmware

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-03-22); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
wl-wn578w2wl-wn578w2_firmware

2 versions affected across 2 products

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-22: 3Mentions · 2026-03-23: 1Technical Details · 2026-03-22: 2Technical Details · 2026-03-23: 103-2203-23
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-223
Disclosure2General1
2026-03-231
Disclosure1
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-4544 A vulnerability was determined in Wavlink WL-WN578W2 221110. This affects an unknown function of the file /cgi-bin/login.cgi of the component POST Request Handler. Exec… https://www.cve.org/CVERecord?id=CVE-2026-4544

    Post summary

    An unspecified vulnerability was identified in the Wavlink WL-WN578W2 device’s /cgi-bin/login.cgi POST handler; details are linked to the CVE record but no PoC, exploit, or patch information is provided.

    00000124
    56.8K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-4544 📊 Severity: 2.4 🚨 Risk Level: Low 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4544 #CVE-2026-4544 #CVE #Low  #CyberSecurity #InfoSec https://t.co/uFuBERTAJG

    Post summary

    The tweet merely announces the existence of CVE-2026-4544 with minimal severity information, serving as a basic disclosure notice.

    0000018
    111 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4544 Cross-Site Scripting in Wavlink WL-WN578W2 via POST Request Handler Argument https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4544

    Post summary

    The post announces a new Cross‑Site Scripting flaw in the Wavlink WL‑WN578W2 router, detailing the trigger via a POST request handler, but offers no PoC, exploit, patch, or evidence of active exploitation.

    0000038
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4544 - Wavlink WL-WN578W2 POST Request login.cgi cross site scripting Intel Report: https://ift.tt/3XR2h0F

    Post summary

    The tweet alerts users about CVE-2026-4544, a cross‑site scripting bug affecting the Wavlink WL‑WN578W2 in the login.cgi POST request, but offers only a link to an Intel Report without providing exploits, patches, or active‑exploitation details.

    0000020
    292 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWwavlinkwl-wn578w2---
OSwavlinkwl-wn578w2_firmware221110--

Explore more