Summary
CVE-2026-18588 is a stack-based buffer overflow (CWE-121 / CWE-119) in the WAVLINK WL-NU516U1 router web interface, affecting firmware build 708c073-mt7628. The flaw resides in the fgets handling within nas.cgi and can be triggered remotely without authentication, resulting in memory corruption and potential remote code execution. It is rated CRITICAL (CVSS v4.0 9.3, CVSS v3.1 9.8).
Technical details
- Root cause: Improper handling of the
CONTENT_LENGTHargument in thefgetsfunction of thenas.cgifile leads to a stack-based buffer overflow. - Trigger conditions: An attacker manipulates the
CONTENT_LENGTHvalue in a request to the vulnerable component; no authentication or user interaction is required. - Attack vector: Network (remote). The exploit is reachable over the device’s web interface.
- Impact: Memory corruption on the stack, enabling denial of service and potential arbitrary code execution with full compromise of confidentiality, integrity, and availability.
Affected software
- WAVLINK WL-NU516U1, firmware build
708c073-mt7628(2026-05-15).
Severity
- CVSS v3.1: 9.8 (CRITICAL) —
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v4.0: 9.3 (CRITICAL) —
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Mitigation and recommended actions
- Immediate: WAVLINK was notified and released a fixed firmware image (build dated 2026-07-13,
4b8a21f-mt7628). Upgrade affected WL-NU516U1 devices to the latest vendor firmware. - If no patch can be applied yet: Restrict access to the router’s web management interface. Ensure the device is not exposed to the internet, and limit administrative access to trusted management networks or VLANs. Disable remote/WAN-side management if enabled.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Page title:
WAVLINK,WAVLINK Router,WAVLINK Mesh Router,WAVLINK WiFi Router - Raw response body:
WAVLINK,Login,Login Now,Device Management,Mesh Router,Device management password,wavlogin.link,wifi.wavlink.com,waplogin.link

