CVE-2026-74843
10.0Wavlink · WN531P3, WN535M1
A stack-based buffer overflow in the Wavlink Export Pingortrace CGI function allows unauthenticated remote attackers to execute arbitrary code via a malicious HTTP_COOKIE.
Executive summary
A critical buffer overflow vulnerability in Wavlink firmware enables unauthenticated remote code execution, posing a severe risk to device integrity.
Vulnerability
The vulnerability exists in the strcpy function within the Export Pingortrace CGI component. An unauthenticated attacker can trigger a stack-based buffer overflow by manipulating the HTTP_COOKIE parameter, leading to potential arbitrary code execution.
Business impact
Successful exploitation of this vulnerability grants an attacker full control over the affected network device. This facilitates unauthorized access to internal network traffic, potential interception of sensitive data, and the ability to pivot into the local environment, resulting in significant security compromise and potential operational downtime. The CVSS score of 10.0 reflects the extreme severity and the triviality of remote exploitation.
Remediation
Immediate Action: Update the affected Wavlink devices to the latest available firmware version provided by the vendor.
Proactive Monitoring: Review web server access logs for anomalous HTTP_COOKIE values or unexpected requests directed at cgi-bin/export_pingortrace.cgi.
Compensating Controls: Implement strict perimeter firewall rules to restrict access to the management interfaces of these devices to trusted management subnets only.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept document is available via GitHub.
Analyst recommendation
Given the critical nature of this vulnerability and the availability of proof-of-concept material, immediate patching is required. Organizations should prioritize updating all affected Wavlink hardware to the latest firmware to prevent unauthorized remote access and potential compromise of the local network.