CVE-2026-2567: Wavlink Wl-NU516U1 Firmware
High severity, CVSS 7.2. EPSS: 1.1% chance of exploitation in the next 30 days.
A vulnerability was detected in Wavlink WL-NU516U1 20251208. This vulnerability affects the function sub_401218 of the file /cgi-bin/nas.cgi. Performing a manipulation of the argument User1Passwd results in stack-based buffer overflow. The attack may be initiated remotely. The exploit is now public and may be used.
Affected products
- Wavlink Wl-NU516U1 Firmware: up to and including 2025-12-08
Published 2026-02-16. Last modified 2026-06-17.