A weakness has been identified in Wavlink WL-WN579A3 220323. This affects the function sub_401F80 of the file /cgi-bin/login.cgi. This manipulation of the argument Hostname causes cross site scripting. Remote exploitation of the attack is possible. Upgrading the affected component is recommended. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
History

Sun, 19 Apr 2026 06:30:00 +0000

Type Values Removed Values Added
First Time appeared Wavlink wl-wn579a3
Vendors & Products Wavlink wl-wn579a3

Sun, 19 Apr 2026 05:45:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in Wavlink WL-WN579A3 220323. This affects the function sub_401F80 of the file /cgi-bin/login.cgi. This manipulation of the argument Hostname causes cross site scripting. Remote exploitation of the attack is possible. Upgrading the affected component is recommended. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Title Wavlink WL-WN579A3 login.cgi sub_401F80 cross site scripting
First Time appeared Wavlink
Wavlink wl-wn579a3 Firmware
Weaknesses CWE-79
CWE-94
CPEs cpe:2.3:o:wavlink:wl-wn579a3_firmware:*:*:*:*:*:*:*:*
Vendors & Products Wavlink
Wavlink wl-wn579a3 Firmware
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:N/E:ND/RL:OF/RC:C'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:X/RL:O/RC:C'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:X/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-04-19T05:15:15.503Z

Reserved: 2026-04-18T15:51:51.155Z

Link: CVE-2026-6559

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-04-19T06:16:10.437

Modified: 2026-04-19T06:16:10.437

Link: CVE-2026-6559

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-19T06:30:05Z