---
id: CVE-2025-10321
title: A flaw has been found in Wavlink WL-WN578W2 221110
summary: >-
  A flaw has been found in Wavlink WL-WN578W2 221110. Impacted is an unknown
  function of the file /live_online.shtml. Executing manipulation can lead to
  information disclosure. The attack can be executed remotely. The exploit has
  been publ…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-200
  - CWE-284
vendor: wavlink
product: wl-wn578w2_firmware
affected:
  - wl-wn578w2_firmware = m78w2_v221110
published: '2025-09-12'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T23:10:00.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-10321'
references:
  - url: >-
      https://github.com/ZZ2266/.github.io/tree/main/WAVLINK/WL-WN578W2/live_online.shtml
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.323747'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.323747'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.643431'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.00531
epssPercentile: 0.42765
ingestedAt: '2026-09-30T23:29:32.383Z'
---

## Overview

A flaw has been found in Wavlink WL-WN578W2 221110. Impacted is an unknown function of the file /live_online.shtml. Executing manipulation can lead to information disclosure. The attack can be executed remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

## Affected

- `wl-wn578w2_firmware = m78w2_v221110`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
