PT-2026-67147 · Wavlink · Wl-Nu516U1

·

CVE-2026-18589

·

Published

2026-08-03

·

Updated

2026-08-03

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Wavlink WL-NU516U1 version 708c073-mt7628
Description A remote attack is possible due to a stack-based buffer overflow, which occurs when the User1Passwd argument is manipulated within the change password() function of the nas.cgi file. A stack-based buffer overflow is a condition where a program writes more data to a buffer located on the stack than the buffer is allocated to hold, potentially leading to crashes or arbitrary code execution.
Recommendations Upgrade the affected component to the fixed version released by the vendor. As a temporary mitigation, restrict access to the nas.cgi file or avoid using the User1Passwd parameter until the update is applied.

Fix

Stack Overflow

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18589

Affected Products

Wl-Nu516U1