Vulnerability Description
A command injection vulnerability in the component /cgi-bin/adm.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commands via a crafted input.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wavlink | Wl-Wn579A3 Firmware | 1.0 |
| Wavlink | Wl-Wn579A3 | - |
Related Weaknesses (CWE)
References
- https://lafdrew.github.io/2025/03/27/Remote-Command-Execution-in-adm-cgi-of-wavlExploitThird Party Advisory
FAQ
What is CVE-2025-44880?
CVE-2025-44880 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A command injection vulnerability in the component /cgi-bin/adm.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commands via a crafted input.
How severe is CVE-2025-44880?
CVE-2025-44880 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-44880?
Check the references section above for vendor advisories and patch information. Affected products include: Wavlink Wl-Wn579A3 Firmware, Wavlink Wl-Wn579A3.