Description
A vulnerability was identified in Wavlink WL-NU516U1 V240425. This vulnerability affects the function sub_401A0C of the file /cgi-bin/login.cgi. Such manipulation of the argument ipaddr leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure.
Problem types
Product status
Timeline
| 2026-03-05: | Advisory disclosed |
| 2026-03-05: | VulDB entry created |
| 2026-03-05: | VulDB entry last update |
Credits
haimianbaobao (VulDB User)
VulDB
References
vuldb.com/?id.349221 (VDB-349221 | Wavlink WL-NU516U1 login.cgi sub_401A0C stack-based overflow)
vuldb.com/?ctiid.349221 (VDB-349221 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/?submit.755341 (Submit #755341 | Wavlink NU516U1 V240425 Stack-based Buffer Overflow)
github.com/...0425/blob/main/ipaddr_Stack Buffer Overflow.md