CVE-2026-74843: Wavlink WN531P3/WN535M1 Export Pingortrace CGI export_pingortrace.cgi strcpy stack-based overflow
A vulnerability was determined in Wavlink WN531P3 and WN535M1 V250922. Affected by this vulnerability is the function strcpy of the file /etc/lighttpd/www/cgi-bin/exportpingortrace.cgi of the component Export Pingortrace CGI. Executing a manipulation of the argument HTTPCOOKIE can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-74843?
CVE-2026-74843 has a critical severity rating of 10.
What type of vulnerability is identified in CVE-2026-74843?
CVE-2026-74843 is a buffer overflow vulnerability.
Which devices are affected by CVE-2026-74843?
CVE-2026-74843 affects the Wavlink WN531P3 and WN535M1 models.
How do I fix CVE-2026-74843?
To fix CVE-2026-74843, you should update the firmware of the affected Wavlink devices to the latest version.
Can CVE-2026-74843 be exploited remotely?
Yes, CVE-2026-74843 can be exploited remotely by manipulating the HTTP_COOKIE argument.