CVE-2026-18607: Wavlink NU516 lighttpd upload.cgi strcpy stack-based overflow

Published Aug 3, 2026
·
Updated

A security vulnerability has been detected in Wavlink WN572, WN570H, WN573, WN529, WN530, WN531, WN535, etc. WN529, WN530, WN531, WN535, WN536, WN551, WN557 and NU516 up to 20260609. Affected by this issue is the function strcpy of the file upload.cgi of the component lighttpd. The manipulation of the argument HTTPCOOKIE leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.

Affected Software

9 affected components
Wavlink WN529<=20260609
Wavlink WN530<=20260609
Wavlink WN531<=20260609
Wavlink WN535<=20260609
Wavlink WN536<=20260609
Wavlink WN551<=20260609
Wavlink WN557<=20260609
Wavlink NU516<=20260609
lighttpd=

Event History

Aug 3, 2026
CVE Published
via MITRE·04:45 PM
Data Sourced
via MITRE·04:45 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-18607?

CVE-2026-18607 has a severity rating of high, with a score of 8.8.

2

What types of devices are affected by CVE-2026-18607?

CVE-2026-18607 affects various Wavlink models including WN529, WN530, WN531, WN535, WN536, WN551, WN557, and NU516.

3

What is the potential impact of CVE-2026-18607?

The vulnerability in CVE-2026-18607 could lead to a stack-based buffer overflow, which may allow for unauthorized code execution.

4

How can I mitigate the risk posed by CVE-2026-18607?

To address CVE-2026-18607, it's critical to update the affected Wavlink devices to the latest firmware version that resolves the issue.

5

What component is exploited in CVE-2026-18607?

CVE-2026-18607 exploits the strcpy function within the upload.cgi component of lighttpd.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203