惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

美团技术团队
IT之家
IT之家
博客园 - Franky
博客园_首页
The Cloudflare Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
量子位
阮一峰的网络日志
阮一峰的网络日志
月光博客
月光博客
V
V2EX
Hugging Face - Blog
Hugging Face - Blog
博客园 - 三生石上(FineUI控件)
M
MIT News - Artificial intelligence
Engineering at Meta
Engineering at Meta
GbyAI
GbyAI
Stack Overflow Blog
Stack Overflow Blog
小众软件
小众软件
Jina AI
Jina AI
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
博客园 - 叶小钗
Apple Machine Learning Research
Apple Machine Learning Research
B
Blog RSS Feed

CXSECURITY Database RSS Feed - CXSecurity.com

Langflow 1.3.0 Remote Code Execution Krayin CRM v2.2.x Authenticated Remote Code Execution PraisonAI CodeAgent <= 1.6.77 Remote Code Execution (RCE) via Unsandboxed LLM Code Execution XenForo XSS CVE Scanner — Passive Detection Tool for CVE-2026-35055, CVE-2026-35054, CVE-2026-35057 KNX visualisering - Broken Access Control 7-Zip <= 26.02 - Mark-of-the-Web (MotW) Bypass via RAR5 Alternate Data Stream Name Collision NodeBB <= 4.13.2 ActivityPub attributedTo Local UID Spoof - CXSecurity.com KNX visualisering - Broken Access Control vm2 <= 3.11.3 - NodeVM Builtin Denylist Bypass SiYuan <= 3.5.9 Remote Code Execution via Malicious Bazaar Package Windows Defender (MsMpEng.exe) Race Condition -> LPE / SYSTEM / Use-After-Free -> Crash D-Link DSL2600U rom-0 Admin Password Disclosure KNX visualisering - Broken Access Control PHP Link Directory (phpLD) 2.1.3 - SQL Injection, IDOR, CSRF OpenEMR 7.0.2 Arbitrary File Read ZTE ZXHN H188A V6 Authentication Bypass phpLD 2.1.3 (EOL) has authenticated SQLi in admin/dir_validate.php (CATEGORY_ID) and admin ORDER BY (sort), unauthenticated IDOR in add_reciprocal.php, CSRF on admin link actions via GET, and exposed install/ after deployment. Verified locally on v2.1.3. Tenable Terrascan Server <= v1.18.3 SSRF and Local File Read Lenovo LegionSpace 1.7.11.2 DAService Unquoted Service Path ZTE H298A / H108N Unauthenticated Credential Exposure WordPress Contest Gallery 28.1.4 Unauthenticated Blind SQL Injection BrandIT Consultancy - Blind Sql Injection Association Management Script - Multiple Vulnerabilities (IDOR, SQLi, Stored XSS) Canvas Breach: Symbiotic Dual-Virus Model & Origin Parity Evidence Open ISES Tickets < 3.44.2 - Hardcoded MySQL Credentials ePati Antikor NGFW 2.0.1301 Authentication Bypass Windows Shell LNK Spoofing to NTLMv2 Hash Capture Apache HTTP Server 2.4.66 mod_http2 Double-Free Denial of Service Grav CMS 2.0.0-beta.2 Remote Code Execution
Wavlink WL-WN579X3-C firewall.cgi UPNP Stack-based Buffer...
2026-03-31 · via CXSECURITY Database RSS Feed - CXSecurity.com

# Exploit Title: Wavlink WL-WN579X3-C firewall.cgi UPNP Stack-based Buffer Overflow # CVE: CVE-2026-5004 # Date: 2026-03-29 # Exploit Author: Mohammed Idrees Banyamer # Author Country: Jordan # Instagram: @banyamer_security # Author GitHub: https://github.com/mbanyamer # Author Blog: https://banyamersecurity.com/blog/ # Vendor Homepage: https://www.wavlink.com # Affected: Wavlink WL-WN579X3-C firmware version 231124 # Tested on: Wavlink WL-WN579X3-C (firmware 231124) # Platform: MIPS # Exploit Type: Remote Stack-based Buffer Overflow # CVSS: 8.8 (High) # Description: A stack-based buffer overflow exists in /cgi-bin/firewall.cgi when the "firewall" parameter is set to "UPNP". The UpnpEnabled parameter is copied into a small 8-byte stack buffer (in function sub_4019FC), but uci_init writes ~40 bytes, causing a 32+ byte overflow that corrupts the saved return address. This vulnerability can be triggered remotely without authentication if the web interface is exposed, leading to Denial of Service (device crash / reboot). With additional ROP engineering, remote code execution may be possible. # References: - https://github.com/Litengzheng/vul_db/blob/main/WL-WN579X3-C/vul_200/README.md - https://vuldb.com/vuln/353891 - https://nvd.nist.gov/vuln/detail/CVE-2026-5004 # Usage: python3 exploit.py <target_ip> # PoC Code:

References:

ttps://github.com/Litengzheng/vul_db/blob/main/WL-WN579X3-C/vul_200/README.md

https://vuldb.com/vuln/353891

https://nvd.nist.gov/vuln/detail/CVE-2026-5004

https://www.thehackerwire.com/wavlink-wl-wn579x3-c-upnp-handler-stack-based-buffer-overflow-cve-2026-5004/




 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.