CVE-2026-5004Disclosure(wavlink / wl-wn579x3-c)

LOWCVSS 7.4 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was determined in Wavlink WL-WN579X3-C 231124. This impacts the function sub_4019FC of the file /cgi-bin/firewall.cgi of the component UPNP Handler. Executing a manipulation of the argument UpnpEnabled can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wl-wn579x3-c
  • wl-wn579x3-c_firmware

Threat summary

  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 5 classified signals
  • Peaked 1d ago at 3 mentions (2026-03-28); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
wl-wn579x3-cwl-wn579x3-c_firmware

2 versions affected across 2 products

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-03-27: 1Mentions · 2026-03-28: 3Mentions · 2026-03-29: 1Technical Details · 2026-03-28: 3Technical Details · 2026-03-29: 103-2703-2803-29
Signal classification1 categories
Disclosure
5100.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-271
Disclosure1
2026-03-283
Disclosure3
2026-03-291
Disclosure1
Full discourse5 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-5004 A vulnerability was determined in Wavlink WL-WN579X3-C 231124. This impacts the function sub_4019FC of the file /cgi-bin/firewall.cgi of the component UPNP Handler. Exe… https://www.cve.org/CVERecord?id=CVE-2026-5004

    Post summary

    The text announces a newly identified vulnerability (CVE‑2026‑5004) in Wavlink WL‑WN579X3‑C, describing the affected function and component.

    0000087
    56.9K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-5004 - High A vulnerability was determined in Wavlink WL-WN579X3-C 231124. This impacts the function sub_4019FC of the file /cgi-bin/firewall.cgi of the component UPNP Handler. Executing a manipulation of... https://www.thehackerwire.com/vulnerability/CVE-2026-5004/ https://t.co/I8NI64c40Q

    Post summary

    A new high‑severity vulnerability (CVE‑2026‑5004) affecting the UPNP handler in Wavlink routers has been disclosed, detailing the impacted function and file but offering no PoC, exploit, or patch announcements.

    0000030
    163 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-5004 - Wavlink WL-WN579X3-C UPNP firewall.cgi sub_4019FC stack-based overflow Intel Report: https://ift.tt/q1Xtl5T

    Post summary

    An Intel report announced a stack‑based overflow vulnerability (CVE-2026-5004) in the Wavlink WL‑WN579X3‑C UPNP firewall.cgi, but no PoC, exploit, or patch details were provided.

    0000022
    283 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-5004: HIGH] A critical stack-based buffer overflow vulnerability impacting Wavlink WL-WN579X3-C 231124's UPNP Handler has been publicly disclosed, allowing remote attacks. The vendor has been unrespo...#cve,CVE-2026-5004,#cybersecurity https://cvefind.com/CVE-2026-5004

    Post summary

    CVE-2026-5004 is a publicly disclosed stack‑based buffer overflow in Wavlink's UPNP handler, enabling remote attacks.

    0000040
    617 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    There is a new vulnerability with elevated criticality in Wavlink WL-WN579X3-C (CVE-2026-5004) https://vuldb.com/?id.353891

    Post summary

    A new critical vulnerability (CVE-2026-5004) has been identified in the Wavlink WL-WN579X3-C device.

    0000064
    2.1K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWwavlinkwl-wn579x3-c---
OSwavlinkwl-wn579x3-c_firmware231124--

Explore more