SYS::ONLINE
Wasteland.
Briefs1680
Issues22
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-18588 2026-08-03

Wavlink WL-NU516U1: Critical Unauthenticated Stack Overflow in nas.cgi (CVE-2026-18588)

"A critical, remotely exploitable stack-based buffer overflow in the Wavlink WL-NU516U1 router allows unauthenticated attackers to corrupt memory via the `CONTENT_LENGTH` argument handled by `nas.cgi`, with a fixed…"

A critical, remotely exploitable stack-based buffer overflow in the Wavlink WL-NU516U1 router allows unauthenticated attackers to corrupt memory via the CONTENT_LENGTH argument handled by nas.cgi, with a fixed firmware version already released by the vendor.

What Is It

CVE-2026-18588 is a stack-based buffer overflow in the fgets function of the file nas.cgi on the Wavlink WL-NU516U1, firmware version 708c073-mt7628. Manipulation of the CONTENT_LENGTH argument triggers the overflow. Remote exploitation is possible. The issue is classified under CWE-119 (improper restriction of operations within the bounds of a memory buffer) and CWE-121 (stack-based buffer overflow). The record was published on 2026-08-03 by VulDB as the CNA and currently carries a vulnerability status of "Received."

Why It Matters

The CVSS v3.1 base score is 9.8 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, network attack vector, low complexity, no privileges, and no user interaction required, with high confidentiality, integrity, and availability impact. The CVSS v4.0 score is 9.3 (CRITICAL) and the legacy CVSS v2.0 score is a maximum 10.0 with complete impact across all three categories. In practical terms, an attacker who can reach the device's web interface over the network needs no credentials and no victim interaction to attempt exploitation.

No CISA KEV entry was supplied for this CVE, so there is no confirmation of active exploitation in the wild at this time.

What's Vulnerable

Patch Status

Patched. The NVD record states the vendor was contacted early, responded professionally, and quickly released a fixed version. The required action is to upgrade the affected component. Wavlink publishes updated firmware at the sysupgrade image referenced below (WINSTAR_NU516U1-WO-A-2026-07-13-4b8a21f-mt7628-squashfs-sysupgrade.bin). Operators running 708c073-mt7628 should flash the fixed firmware and, until then, restrict network access to the device's management interface.

Sources