CVE-2026-18589: Wavlink WL-NU516U1 nas.cgi change_password stack-based overflow
A vulnerability was found in Wavlink WL-NU516U1 708c073-mt7628. This impacts the function changepassword of the file nas.cgi. The manipulation of the argument User1Passwd results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used. The affected component should be upgraded. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18589?
CVE-2026-18589 has a critical severity score of 9.8.
How do I fix CVE-2026-18589?
To fix CVE-2026-18589, update the Wavlink WL-NU516U1 firmware to the latest version provided by the manufacturer.
What type of vulnerability is CVE-2026-18589?
CVE-2026-18589 is a stack-based buffer overflow vulnerability.
Can CVE-2026-18589 be exploited remotely?
Yes, CVE-2026-18589 can be exploited remotely, making it particularly dangerous.
What component is affected by CVE-2026-18589?
CVE-2026-18589 affects the change_password function in the nas.cgi file of Wavlink WL-NU516U1.