๐Ÿ” CVE Alert

CVE-2026-18607

HIGH 8.8

Wavlink NU516 lighttpd upload.cgi strcpy stack-based overflow

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

A security vulnerability has been detected in Wavlink WN572, WN570H, WN573, WN529, WN530, WN531, WN535, etc. WN529, WN530, WN531, WN535, WN536, WN551, WN557 and NU516 up to 20260609. Affected by this issue is the function strcpy of the file upload.cgi of the component lighttpd. The manipulation of the argument HTTP_COOKIE leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.

CWE CWE-121 CWE-119
Vendor wavlink
Product wn572
Published Aug 3, 2026
Stay Ahead of the Next One

Get instant alerts for wavlink wn572

Be the first to know when new high vulnerabilities affecting wavlink wn572 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Wavlink / WN572
20260609
Wavlink / WN570H
20260609
Wavlink / WN573
20260609
Wavlink / WN529
20260609
Wavlink / WN530
20260609
Wavlink / WN531
20260609
Wavlink / WN535
20260609
Wavlink / etc. WN529
20260609
Wavlink / WN530
20260609
Wavlink / WN531
20260609
Wavlink / WN535
20260609
Wavlink / WN536
20260609
Wavlink / WN551
20260609
Wavlink / WN557
20260609
Wavlink / NU516
20260609

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/385530 vuldb.com: https://vuldb.com/vuln/385530/cti vuldb.com: https://vuldb.com/cve/CVE-2026-18607 vuldb.com: https://vuldb.com/submit/852637 github.com: https://github.com/0xcc12138/WAVLINK-vul

Credits

๐Ÿ” 0xcc12138 (VulDB User)