PT-2026-8382 · Wavlink · Wavlink Wl-Nu516U1

Haimianbaobao

·

Published

2026-02-04

·

Updated

2026-02-16

·

CVE-2026-2567

CVSS v2.0

9.0

High

AV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Wavlink WL-NU516U1 version 20251208
Description A stack-based buffer overflow exists in the sub 401218 function of the /cgi-bin/nas.cgi file. The issue is triggered by manipulating the User1Passwd argument. This allows for remote attacks. A public exploit is available.
Recommendations Restrict access to the /cgi-bin/nas.cgi file. Avoid manipulating the User1Passwd argument. As a temporary workaround, consider restricting admin access.

Exploit

Fix

Buffer Overflow

Stack Overflow

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2026-02351
CVE-2026-2567

Affected Products

Wavlink Wl-Nu516U1