CVE-2026-18607

Summary

A security vulnerability has been detected in Wavlink WN572, WN570H, WN573, WN529, WN530, WN531, WN535, etc. WN529, WN530, WN531, WN535, WN536, WN551, WN557 and NU516 up to 20260609. Affected by this issue is the function strcpy of the file upload.cgi of the component lighttpd. The manipulation of the argument HTTP_COOKIE leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.

Affected Software

VendorProductVersion RangeStatus
WavlinkWN57220260609affected
WavlinkWN570H20260609affected
WavlinkWN57320260609affected
WavlinkWN52920260609affected
WavlinkWN53020260609affected
WavlinkWN53120260609affected
WavlinkWN53520260609affected
Wavlinketc. WN52920260609affected
WavlinkWN53020260609affected
WavlinkWN53120260609affected
WavlinkWN53520260609affected
WavlinkWN53620260609affected
WavlinkWN55120260609affected
WavlinkWN55720260609affected
WavlinkNU51620260609affected

Weaknesses

  • CWE-121: Stack-based Buffer Overflow
  • CWE-119: Memory Corruption

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: no
    • Technical Impact: total

References