WAVLINK-SA-2026-080303: Stack-based Buffer Overflow in WL-NU516U1

Published 2026-08-03 10:00 UTC+8
Severity Critical
Status Analyzed

Abstract

A vulnerability was found in Wavlink WL-NU516U1 708c073-mt7628. This impacts the function change_password of the file nas.cgi. The manipulation of the argument User1Passwd results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used. The affected component should be upgraded. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

Affected Products

ProductAffected FirmwareFixed FirmwareAvailability
WL-NU516U1 Wi-Fi Router M16U1_V251208 and earlier M16U1_V260713 Available now · Download

Detail

A vulnerability was found in Wavlink WL-NU516U1 708c073-mt7628. This impacts the function change_password of the file nas.cgi. The manipulation of the argument User1Passwd results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used. The affected component should be upgraded. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product. Tracked as CVE-2026-18589 · CVSS v3.1 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

Solution

Update the firmware to version M16U1_V260713 or later.

Acknowledgement

Thanks to oduoke567 for reporting this vulnerability.

Reference

CVE-2026-18589 · NVD entry