CVE-2026-18607
Wavlink NU516 lighttpd upload.cgi strcpy stack-based overflow
CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th
A security vulnerability has been detected in Wavlink WN572, WN570H, WN573, WN529, WN530, WN531, WN535, etc. WN529, WN530, WN531, WN535, WN536, WN551, WN557 and NU516 up to 20260609. Affected by this issue is the function strcpy of the file upload.cgi of the component lighttpd. The manipulation of the argument HTTP_COOKIE leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.
| CWE | CWE-121 CWE-119 |
| Vendor | wavlink |
| Product | wn572 |
| Published | Aug 3, 2026 |
Stay Ahead of the Next One
Get instant alerts for wavlink wn572
Be the first to know when new high vulnerabilities affecting wavlink wn572 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
Wavlink / WN572
20260609
Wavlink / WN570H
20260609
Wavlink / WN573
20260609
Wavlink / WN529
20260609
Wavlink / WN530
20260609
Wavlink / WN531
20260609
Wavlink / WN535
20260609
Wavlink / etc. WN529
20260609
Wavlink / WN530
20260609
Wavlink / WN531
20260609
Wavlink / WN535
20260609
Wavlink / WN536
20260609
Wavlink / WN551
20260609
Wavlink / WN557
20260609
Wavlink / NU516
20260609
References
Credits
๐ 0xcc12138 (VulDB User)