Stack-based Buffer Overflow in Wavlink WL-NU516U1
CVE-2026-18588
9.3CRITICAL
What is CVE-2026-18588?
A vulnerability exists in the Wavlink WL-NU516U1 device, specifically within the nas.cgi file's fgets function. An attacker can manipulate the CONTENT_LENGTH argument, potentially resulting in a stack-based buffer overflow that may allow for remote exploitation of the device. The vendor has acknowledged the issue and promptly released a firmware update to address the vulnerability, ensuring users have a secure version of the product.
Affected Version(s)
WL-NU516U1 708c073-mt7628
