VYPR
High severity7.2NVD Advisory· Published Mar 6, 2026· Updated Jun 17, 2026

CVE-2026-3613

CVE-2026-3613

Description

A vulnerability was identified in Wavlink WL-NU516U1 V240425. This vulnerability affects the function sub_401A0C of the file /cgi-bin/login.cgi. Such manipulation of the argument ipaddr leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure.

Affected products

3
  • cpe:2.3:o:wavlink:wl-nu516u1_firmware:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:wavlink:wl-nu516u1_firmware:*:*:*:*:*:*:*:*range: V240425
    • cpe:2.3:o:wavlink:wl-nu516u1_firmware:m16u1_v240425:*:*:*:*:*:*:*
  • Wavlink/NU516U1llm-fuzzy
    Range: V240425

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.