A vulnerability was determined in Wavlink WL-WN579X3-C 231124. This impacts the function sub_4019FC of the file /cgi-bin/firewall.cgi of the component UPNP Handler. Executing a manipulation of the argument UpnpEnabled can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
Affected Vendors & Products
References
History
Sat, 28 Mar 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was determined in Wavlink WL-WN579X3-C 231124. This impacts the function sub_4019FC of the file /cgi-bin/firewall.cgi of the component UPNP Handler. Executing a manipulation of the argument UpnpEnabled can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | Wavlink WL-WN579X3-C UPNP firewall.cgi sub_4019FC stack-based overflow | |
| First Time appeared |
Wavlink
Wavlink wl-wn579x3-c Firmware |
|
| Weaknesses | CWE-119 CWE-121 |
|
| CPEs | cpe:2.3:o:wavlink:wl-wn579x3-c_firmware:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Wavlink
Wavlink wl-wn579x3-c Firmware |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2026-03-28T17:30:12.944Z
Updated: 2026-03-28T17:30:12.944Z
Reserved: 2026-03-27T13:51:13.122Z
Link: CVE-2026-5004
No data.
Status : Received
Published: 2026-03-28T18:15:57.917
Modified: 2026-03-28T18:15:57.917
Link: CVE-2026-5004
No data.