Security Advisory

Protecting our customers from security threats is always a top priority at WAVLINK. We strive to provide secure and stable products and services, strictly protect the privacy and security of user data, and welcome responsible security research.

Security Assurance

Product Security First

We are committed to providing secure and stable products and services, with strict protection of user data privacy.

Responsible Vulnerability Handling

We maintain a security response process covering receipt, verification, remediation, and disclosure. We endeavor to respond to reports promptly (usually within five working days).

Coordinated Disclosure

We endeavor to disclose vulnerabilities and publish fixes within 90 days of report. For complex cases, we will agree on a disclosure timeline with the reporter. Actively exploited vulnerabilities will be expedited.

Compliance & Notification

We fulfill our security obligations under applicable laws and regulations, and keep users informed with essential security information in a timely manner.

Open Collaboration

We welcome and encourage reports on product security and user privacy, and provide convenient channels for submission.

Reporting Channel

We will endeavor to acknowledge and respond to your report within five working days.
๐Ÿ“„ Please complete the Potential Vulnerability Report Form (Excel, v1.0) and attach it to your email to speed up our handling.

Reporting Guidelines

  1. We recommend using the Potential Vulnerability Report Form provided on this page. Reports must be based on the latest firmware release, preferably written in English, and include the firmware version, reproduction steps, and impact description.
  2. Please submit through the dedicated channel above and do not disclose vulnerability details publicly. Reports received through other channels will be forwarded to the dedicated channel, but we cannot guarantee that they will be acknowledged.
  3. Please maintain communication and cooperation throughout the disclosure process, and refrain from disclosing vulnerability information before the agreed disclosure date.
  4. Do not exploit vulnerabilities in ways that affect real user data or devices.

Our Process

Receipt
โ†’
Verification
โ†’
Remediation
โ†’
Disclosure

Security Advisories

Advisory IDTypeCVEAffected ModelsSeverityStatusDate
WAVLINK-SA-2026-062902 Stack-based Buffer Overflow CVE-2026-13539 WL-NU516U1-A High Analyzed 2026-06-29
WAVLINK-SA-2026-071301 Command Injection CVE-2026-15513 WL-NU516U1 Medium Analyzed 2026-07-13
WAVLINK-SA-2026-080301 Command Injection CVE-2026-18587 WL-NU516U1 High Analyzed 2026-08-03
WAVLINK-SA-2026-080302 Stack-based Buffer Overflow CVE-2026-18588 WL-NU516U1 Critical Analyzed 2026-08-03
WAVLINK-SA-2026-080303 Stack-based Buffer Overflow CVE-2026-18589 WL-NU516U1 Critical Analyzed 2026-08-03
WAVLINK-SA-2026-080304 Command Injection CVE-2026-18590 WL-NU516U1 Medium Analyzed 2026-08-03
Under active investigation.

Severity ratings are based on CVSS v3.1: Critical 9.0โ€“10.0 ยท High 7.0โ€“8.9 ยท Medium 4.0โ€“6.9 ยท Low 0.1โ€“3.9.
Click an advisory ID to view details, including affected firmware versions, solutions, acknowledgments, and timeline.