CVE-2026-18589
Wavlink · WL-NU516U1
A stack-based buffer overflow in the nas.cgi component of Wavlink WL-NU516U1 allows remote unauthenticated attackers to execute arbitrary code via the User1Passwd argument.
Executive summary
A critical remote code execution vulnerability in Wavlink WL-NU516U1 firmware poses a severe risk of full system compromise for affected devices.
Vulnerability
This is a stack-based buffer overflow vulnerability occurring in the change_password function within the nas.cgi file. The vulnerability is exploitable remotely by an unauthenticated attacker who can send a crafted request to the User1Passwd argument.
Business impact
Successful exploitation of this flaw allows an attacker to execute arbitrary code with elevated privileges on the affected networking device. This could lead to complete system takeover, unauthorized access to network traffic, and the potential for lateral movement into the internal network. Given the CVSS score of 9.8, this vulnerability is classified as critical and requires immediate attention to prevent unauthorized access.
Remediation
Immediate Action: Update the Wavlink WL-NU516U1 firmware to the latest version provided by the vendor to patch the buffer overflow vulnerability.
Proactive Monitoring: Monitor network traffic and device logs for suspicious access requests to the nas.cgi file, specifically focusing on unusually long input strings in password fields.
Compensating Controls: Deploy a Web Application Firewall (WAF) or an Intrusion Prevention System (IPS) to filter malicious requests containing abnormally large payloads targeted at the nas.cgi endpoint.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept report is available via GitHub.
Analyst recommendation
The critical severity of this vulnerability, combined with the availability of public technical details, necessitates an immediate patching cycle. Administrators should prioritize upgrading all affected Wavlink WL-NU516U1 devices to the vendor-supplied firmware release to eliminate the underlying memory corruption risk.