A critical, remotely exploitable stack-based buffer overflow in the Wavlink WL-NU516U1 router allows unauthenticated attackers to corrupt memory via the CONTENT_LENGTH argument handled by nas.cgi, with a fixed firmware version already released by the vendor.
What Is It
CVE-2026-18588 is a stack-based buffer overflow in the fgets function of the file nas.cgi on the Wavlink WL-NU516U1, firmware version 708c073-mt7628. Manipulation of the CONTENT_LENGTH argument triggers the overflow. Remote exploitation is possible. The issue is classified under CWE-119 (improper restriction of operations within the bounds of a memory buffer) and CWE-121 (stack-based buffer overflow). The record was published on 2026-08-03 by VulDB as the CNA and currently carries a vulnerability status of "Received."
Why It Matters
The CVSS v3.1 base score is 9.8 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, network attack vector, low complexity, no privileges, and no user interaction required, with high confidentiality, integrity, and availability impact. The CVSS v4.0 score is 9.3 (CRITICAL) and the legacy CVSS v2.0 score is a maximum 10.0 with complete impact across all three categories. In practical terms, an attacker who can reach the device's web interface over the network needs no credentials and no victim interaction to attempt exploitation.
No CISA KEV entry was supplied for this CVE, so there is no confirmation of active exploitation in the wild at this time.
What's Vulnerable
- Vendor: Wavlink
- Product: WL-NU516U1 (CPE:
cpe:2.3:o:wavlink:wl-nu516u1_firmware) - Affected version:
708c073-mt7628 - Affected component: the
fgetsfunction innas.cgi, reached via theCONTENT_LENGTHargument
Patch Status
Patched. The NVD record states the vendor was contacted early, responded professionally, and quickly released a fixed version. The required action is to upgrade the affected component. Wavlink publishes updated firmware at the sysupgrade image referenced below (WINSTAR_NU516U1-WO-A-2026-07-13-4b8a21f-mt7628-squashfs-sysupgrade.bin). Operators running 708c073-mt7628 should flash the fixed firmware and, until then, restrict network access to the device's management interface.