Security Advisory
Protecting our customers from security threats is always a top priority at WAVLINK. We strive to provide secure and stable products and services, strictly protect the privacy and security of user data, and welcome responsible security research.
Security Assurance
Product Security First
We are committed to providing secure and stable products and services, with strict protection of user data privacy.
Responsible Vulnerability Handling
We maintain a security response process covering receipt, verification, remediation, and disclosure. We endeavor to respond to reports promptly (usually within five working days).
Coordinated Disclosure
We endeavor to disclose vulnerabilities and publish fixes within 90 days of report. For complex cases, we will agree on a disclosure timeline with the reporter. Actively exploited vulnerabilities will be expedited.
Compliance & Notification
We fulfill our security obligations under applicable laws and regulations, and keep users informed with essential security information in a timely manner.
Open Collaboration
We welcome and encourage reports on product security and user privacy, and provide convenient channels for submission.
Reporting Channel
Reporting Guidelines
- We recommend using the Potential Vulnerability Report Form provided on this page. Reports must be based on the latest firmware release, preferably written in English, and include the firmware version, reproduction steps, and impact description.
- Please submit through the dedicated channel above and do not disclose vulnerability details publicly. Reports received through other channels will be forwarded to the dedicated channel, but we cannot guarantee that they will be acknowledged.
- Please maintain communication and cooperation throughout the disclosure process, and refrain from disclosing vulnerability information before the agreed disclosure date.
- Do not exploit vulnerabilities in ways that affect real user data or devices.
Our Process
Security Advisories
| Advisory ID | Type | CVE | Affected Models | Severity | Status | Date |
|---|---|---|---|---|---|---|
| WAVLINK-SA-2026-062902 | Stack-based Buffer Overflow | CVE-2026-13539 | WL-NU516U1-A | High | Analyzed | 2026-06-29 |
| WAVLINK-SA-2026-071301 | Command Injection | CVE-2026-15513 | WL-NU516U1 | Medium | Analyzed | 2026-07-13 |
| WAVLINK-SA-2026-080301 | Command Injection | CVE-2026-18587 | WL-NU516U1 | High | Analyzed | 2026-08-03 |
| WAVLINK-SA-2026-080302 | Stack-based Buffer Overflow | CVE-2026-18588 | WL-NU516U1 | Critical | Analyzed | 2026-08-03 |
| WAVLINK-SA-2026-080303 | Stack-based Buffer Overflow | CVE-2026-18589 | WL-NU516U1 | Critical | Analyzed | 2026-08-03 |
| WAVLINK-SA-2026-080304 | Command Injection | CVE-2026-18590 | WL-NU516U1 | Medium | Analyzed | 2026-08-03 |
Severity ratings are based on CVSS v3.1: Critical 9.0โ10.0 ยท High 7.0โ8.9 ยท Medium 4.0โ6.9 ยท Low 0.1โ3.9.
Click an advisory ID to view details, including affected firmware versions, solutions, acknowledgments, and timeline.