A vulnerability has been found in Wavlink WL-NU516U1 708c073-mt7628. This affects the function fgets of the file nas.cgi. The manipulation of the argument CONTENT_LENGTH leads to stack-based buffer overflow. Remote exploitation of the attack is possible. You should upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Metrics
Affected Vendors & Products
References
History
Mon, 03 Aug 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wavlink wl-nu516u1
|
|
| Vendors & Products |
Wavlink wl-nu516u1
|
Mon, 03 Aug 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been found in Wavlink WL-NU516U1 708c073-mt7628. This affects the function fgets of the file nas.cgi. The manipulation of the argument CONTENT_LENGTH leads to stack-based buffer overflow. Remote exploitation of the attack is possible. You should upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product. | |
| Title | Wavlink WL-NU516U1 nas.cgi fgets stack-based overflow | |
| First Time appeared |
Wavlink
Wavlink wl-nu516u1 Firmware |
|
| Weaknesses | CWE-119 CWE-121 |
|
| CPEs | cpe:2.3:o:wavlink:wl-nu516u1_firmware:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Wavlink
Wavlink wl-nu516u1 Firmware |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2026-08-03T06:00:11.107Z
Updated: 2026-08-03T06:00:11.107Z
Reserved: 2026-08-02T20:33:29.434Z
Link: CVE-2026-18588
No data.
No data.
No data.