Saltcorn
Multiple Products
Saltcorn is an extensible, open source, no-code database application builder. Prior to 1.4.6, 1.5.6, and 1.6.0-beta.5, a SQL injection vulnerability i...
2026-04-25
Description
Saltcorn is an extensible, open source, no-code database application builder. Prior to 1.4.6, 1.5.6, and 1.6.0-beta.5, a SQL injection vulnerability in Saltcorn’s mobile-sync routes allows any authenticated low-privilege user with read access to at least one table to inject arbitrary SQL through sync parameters. This can lead to full database exfiltration, including admin password hashes and configuration secrets, and may also enable database modification or destruction depending on the backend. This vulnerability is fixed in 1.4.6, 1.5.6, and 1.6.0-beta.5.
AI Analyst Comment
Remediation
Update Saltcorn Multiple Products to the latest version. Check vendor security advisory for specific patch details. Monitor for exploitation attempts and review access logs.
---METADATA---
VENDOR: Wavlink
PRODUCT: WL-WN579A3
AFFECTED_VERSIONS: 220323
---END_METADATA---
Description Summary:
A command injection vulnerability in the SetName/GuestWifi function of Wavlink WL-WN579A3 firmware allows remote attackers to execute arbitrary commands via POST requests.
Executive Summary:
Wavlink WL-WN579A3 routers are vulnerable to a critical remote command injection flaw that allows attackers to take full control of the device.
Vulnerability Details
CVE-ID: CVE-2026-4163
Affected Software: Wavlink WL-WN579A3
Affected Versions: 220323
Vulnerability: The vulnerability is located in the
SetName/GuestWififunction within/cgi-bin/wireless.cgi. By manipulating POST requests, a remote attacker can bypass input validation and execute arbitrary system commands on the device.Business Impact
A successful exploit allows an attacker to intercept network traffic, change DNS settings, or enlist the device into a botnet. Given the CVSS score of 9.8, the impact is Critical, as it compromises the gateway of the local network, potentially exposing all connected devices to further attacks.
Remediation Plan
Immediate Action: Upgrade the Wavlink WL-WN579A3 firmware to the latest available version immediately.
Proactive Monitoring: Check router logs for suspicious POST requests directed at
/cgi-bin/wireless.cgiand monitor for unauthorized changes to Wi-Fi configurations.Compensating Controls: Disable remote management interfaces and ensure that the administrative interface is not accessible from the public internet.
Exploitation Status
Public Exploit Available: Yes
Analyst Notes: As of March 16, 2026, a public exploit is available. This significantly increases the risk of active exploitation, as the barrier to entry for attackers is now minimal.
Analyst Recommendation
Because a public exploit exists, this vulnerability must be remediated with the highest urgency. Administrators should flash the updated firmware immediately and verify that the device has not already been compromised by checking for unauthorized persistent scripts.