Wavlink · Wl-Nu516U1-A · CVE-2026-13539
**Name of the Vulnerable Software and Affected Versions**
Wavlink WL-NU516U1-A version M16U1 V240425
**Description**
A stack-based buffer overflow occurs in the POST Parameter Handler component when processing the `Guest ssid` argument. This issue exists within the `sub 407504()` function of the '/cgi-bin/wireless.cgi' endpoint and can be exploited remotely.
**Recommendations**
Upgrade the affected component to the fixed version released by the vendor.