CVE-2026-7690Disclosure(wavlink / wl-wn570ha1)

LOWCVSS 9.8 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch wavlink wl-wn570ha1 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A weakness has been identified in Wavlink WL-WN570HA1 R70HA1 V1410_221110. This issue affects the function set_sys_adm of the file /cgi-bin/adm.cgi. This manipulation of the argument Username causes command injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. Once again the vendors acted very professional and confirms, "that the WN570HA1 firmware version R70HA1 V1410_221110 has been removed from our website." This vulnerability only affects products that are no longer supported by the maintainer.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-77

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wl-wn570ha1
  • wl-wn570ha1_firmware

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 4 total mentions across 1 day

Affected systems

Vendors
Products
wl-wn570ha1wl-wn570ha1_firmware

2 versions affected across 2 products

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-05-03: 4Patch / Workaround · 2026-05-03: 1Technical Details · 2026-05-03: 405-03
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Patch
125.0%
Referenced assets5 URLs
Full discourse4 posts
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Patch

    🌐 Network Security Alert: Multiple Command Injection vulnerabilities (CVE-2026-7690, 7691, 7692) identified in Wavlink WL-WN570HA1. If you manage these devices, check for firmware updates immediately. Source: https://vuldb.com/vuln/360863

    Post summary

    The alert identifies command injection vulnerabilities in Wavlink WL-WN570HA1 devices and urges users to apply firmware updates to mitigate the risk.

    1000032
    1.3K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-7690 A weakness has been identified in Wavlink WL-WN570HA1 R70HA1 V1410_221110. This issue affects the function set_sys_adm of the file /cgi-bin/adm.cgi. This manipulation o… https://www.cve.org/CVERecord?id=CVE-2026-7690 ----- Traducción: CVE-2026-7690 Se … http://infoflow.cloud`

    Post summary

    CVE‑2026‑7690 is a newly disclosed weakness affecting the set_sys_adm function in the /cgi-bin/adm.cgi file of Wavlink WL‑WN570HA1 routers, with no evident exploit, PoC, or patch information provided.

    0000025
    75 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-7690 A weakness has been identified in Wavlink WL-WN570HA1 R70HA1 V1410_221110. This issue affects the function set_sys_adm of the file /cgi-bin/adm.cgi. This manipulation o… https://www.cve.org/CVERecord?id=CVE-2026-7690

    Post summary

    This brief announcement identifies CVE-2026-7690 as a weakness in a Wavlink router’s set_sys_adm function, offering limited technical detail but no evidence of exploitation or patch information.

    00000264
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-7690 Command Injection in Wavlink WL-WN570HA1 R70HA1 V1410_221110 via U... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7690 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    A CVE-2026-7690 alert noting a command injection vulnerability in a Wavlink device, with a link to vulmon but no PoC, exploit, patch, or active exploitation details.

    0000043
    4.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWwavlinkwl-wn570ha1---
OSwavlinkwl-wn570ha1_firmwarer70ha1_v1410_221110--

Explore more