peter bassill · operator
$ cve CVE-2026-4163 JSON

CVE-2026-4163

9.8
CRITICAL · CVSS 3.1 · EPSS 3.6% (pctl 89)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

A vulnerability was detected in Wavlink WL-WN579A3 220323. This issue affects the function SetName/GuestWifi of the file /cgi-bin/wireless.cgi of the component POST Request Handler. Performing a manipulation results in command injection. It is possible to initiate the attack remotely. The exploit is now public and may be used. Upgrading the affected component is recommended.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.57% — more likely to be exploited than 89% of all CVEs
WeaknessCWE-74
On CISA KEVno
Public exploitnone known
Published2026-03-16
Last modified2026-06-17

References

→ the Explorer  ·  watch your stack  ·  NVD