LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →

CVE-2026-4164 - Vulnerability Analysis

CriticalCVSS: 9.8

Last Updated: March 16, 2026

Wavlink WL-WN578W2 - Command Injection

Published: March 16, 2026Updated: March 16, 2026Remote Exploitable

Overview

Wavlink WL-WN578W2 221110 contains a command injection caused by manipulation in Delete_Mac_list/SetName/GuestWifi functions in /cgi-bin/wireless.cgi POST Request Handler, letting remote attackers execute arbitrary commands, exploit requires crafted POST request.

Severity & Score

Severity: Critical
CVSS Score: 9.8
EPSS Score: 16.7%(Probability of exploitation in next 30 days)

Impact

Remote attackers can execute arbitrary commands, potentially taking full control of the device.

Mitigation

Upgrade to the latest version of the affected component.

Social Media Activity(2 posts)

TheHackerWire
TheHackerWire
@thehackerwire
Mar 16, 2026

šŸ”“ CVE-2026-4164 - Critical (9.8) A flaw has been found in Wavlink WL-WN578W2 221110. Impacted is the function Delete_Mac_list/SetName/GuestWifi of the file /cgi-bin/wireless.cgi of the component POST Request Handler. Executing a manipulation can lead to command injection. It is p... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-4164/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Mar 16, 2026

šŸ”“ CVE-2026-4164 - Critical (9.8) A flaw has been found in Wavlink WL-WN578W2 221110. Impacted is the function Delete_Mac_list/SetName/GuestWifi of the file /cgi-bin/wireless.cgi of the component POST Request Handler. Executing a manipulation can lead to command injection. It is p... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-4164/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-4164
Severity
Critical
CVSS Score
9.8
Type
command_injection
Status
unconfirmed
EPSS
16.7%
Social Posts
2

CWE

  • CWE-74

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Score

16.7%Probability of exploitation in the next 30 days