CVE-2026-3613: Wavlink Wl-NU516U1 Firmware
High severity, CVSS 7.2. EPSS: 1.2% chance of exploitation in the next 30 days.
A vulnerability was identified in Wavlink WL-NU516U1 V240425. This vulnerability affects the function sub_401A0C of the file /cgi-bin/login.cgi. Such manipulation of the argument ipaddr leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure.
Affected products
- Wavlink Wl-NU516U1 Firmware: version m16u1_v240425 only
Published 2026-03-06. Last modified 2026-06-17.