CVE-2026-18588
Wavlink · WL-NU516U1
The Wavlink WL-NU516U1 router contains a stack-based buffer overflow vulnerability in the nas.cgi file, which can be triggered by manipulating the CONTENT_LENGTH argument.
Executive summary
A stack-based buffer overflow in the Wavlink WL-NU516U1 router allows an unauthenticated remote attacker to execute arbitrary code or crash the device.
Vulnerability
The vulnerability exists in the fgets function within the nas.cgi component. An unauthenticated attacker can send a crafted request with a malicious CONTENT_LENGTH value, causing memory corruption on the stack.
Business impact
Successful exploitation allows for remote code execution with the privileges of the web service, leading to full system compromise. Given the critical CVSS score of 9.8, the potential for device takeover, data exfiltration, and persistent access within a private network is extremely high.
Remediation
Immediate Action: Update the Wavlink WL-NU516U1 firmware to the version provided by the vendor (WINSTAR_NU516U1-WO-A-2026-07-13-4b8a21f-mt7628-squashfs-sysupgrade.bin).
Proactive Monitoring: Monitor network traffic for anomalous HTTP POST requests directed at nas.cgi that contain unusually large or malformed header values.
Compensating Controls: Restrict access to the router management interface to trusted internal IP addresses and employ a WAF to filter out malformed HTTP requests.
Exploitation status
Public Exploit Available: Yes — a public report and proof-of-concept repository exist on GitHub.
Analyst recommendation
This vulnerability is highly severe and easily reachable from the network. Immediate firmware updates are required to prevent potential remote code execution. If patching is not immediately possible, disable remote management features and restrict access to the device management interface.