CVE-2026-18588
Severity CVSS v4.0:
CRITICAL
Type:
CWE-119
Buffer Errors
Publication date:
03/08/2026
Last modified:
12/08/2026
Description
A vulnerability has been found in Wavlink WL-NU516U1 708c073-mt7628. This affects the function fgets of the file nas.cgi. The manipulation of the argument CONTENT_LENGTH leads to stack-based buffer overflow. Remote exploitation of the attack is possible. You should upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Impact
Base Score 4.0
9.30
Severity 4.0
CRITICAL
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
10.00
Severity 2.0
HIGH
References to Advisories, Solutions, and Tools
- https://dl.wavlink.com/firmware/RD/WINSTAR_NU516U1-WO-A-2026-07-13-4b8a21f-mt7628-squashfs-sysupgrade.bin
- https://github.com/oduoke567/WAVLINK-NU516U1-2026-05-1/blob/main/report2.md
- https://vuldb.com/cve/CVE-2026-18588
- https://vuldb.com/submit/850500
- https://vuldb.com/vuln/385416
- https://vuldb.com/vuln/385416/cti
- https://vuldb.com/submit/850500



