CVE-2026-18607
HIGHWavlink NU516 lighttpd upload.cgi strcpy stack-based overflow
Title source: cnaDescription
A security vulnerability has been detected in Wavlink WN572, WN570H, WN573, WN529, WN530, WN531, WN535, etc. WN529, WN530, WN531, WN535, WN536, WN551, WN557 and NU516 up to 20260609. Affected by this issue is the function strcpy of the file upload.cgi of the component lighttpd. The manipulation of the argument HTTP_COOKIE leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.
References (5)
Core 5
Core References
Vdb Entry, Technical Description vdb-entry
technical-description
VDB-385530 | Wavlink NU516 lighttpd upload.cgi strcpy stack-based overflow
https://vuldb.com/vuln/385530
Signature, Permissions Required signature
permissions-required
VDB-385530 | CTI Indicators (IOB, IOC, IOA)
https://vuldb.com/vuln/385530/cti
Third Party Advisory third-party-advisory
CVE-2026-18607 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-18607
Third Party Advisory third-party-advisory
Submit #852637 | WAVLINK Multiple Router Series (WN572, WN570H, WN573, WN529, WN530, WN531, WN535, etc.) WN529, WN530, WN531, WN535, WN536, WN551, WN557, NU516,and so on Stack-based Buffer Overflow
https://vuldb.com/submit/852637
Scores
CVSS v3
8.8
EPSS
0.0044
EPSS Percentile
36.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-119
CWE-121
Status
published
Products (12)
Wavlink/etc. WN529
20260609
Wavlink/NU516
20260609
Wavlink/WN529
20260609
Wavlink/WN530
20260609
Wavlink/WN531
20260609
Wavlink/WN535
20260609
Wavlink/WN536
20260609
Wavlink/WN551
20260609
Wavlink/WN557
20260609
Wavlink/WN570H
20260609
... and 2 more
Published
Aug 03, 2026
Tracked Since
Aug 03, 2026