Stack-based Buffer Overflow in Wavlink WL-NU516U1
CVE-2026-18588

9.3CRITICAL

Key Information:

Vendor

Wavlink

Vendor
CVE Published:
3 August 2026

What is CVE-2026-18588?

A vulnerability exists in the Wavlink WL-NU516U1 device, specifically within the nas.cgi file's fgets function. An attacker can manipulate the CONTENT_LENGTH argument, potentially resulting in a stack-based buffer overflow that may allow for remote exploitation of the device. The vendor has acknowledged the issue and promptly released a firmware update to address the vulnerability, ensuring users have a secure version of the product.

Affected Version(s)

WL-NU516U1 708c073-mt7628

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

oduoke (VulDB User)
VulDB CNA Team
.