← Vulnerability feed

Vulnerability record · CVE-2026-3613 · published 6 March 2026

CVE-2026-3613: Wavlink wl-nu516u1 firmware memory buffer overflow vulnerability

Wavlink · Wl Nu516u1 Firmware

A vulnerability was identified in Wavlink WL-NU516U1 V240425. This vulnerability affects the function sub_401A0C of the file /cgi-bin/login.cgi. Such manipulation of the argument ipaddr leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure.

7.3 CVSS 4.0 High EPSS 1.1% · top 34.9% CWE-119 · Memory buffer overflowCWE-121 · Stack-based buffer overflow
7.3CVSS 4.0 base score, v2 8.3
1.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

A vulnerability was identified in Wavlink WL-NU516U1 V240425. This vulnerability affects the function sub_401A0C of the file /cgi-bin/login.cgi. Such manipulation of the argument ipaddr leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure.

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/Wlz1112/WAVLINK-NU516-V240425/blob/main/ipaddr_Stack%20Buffer%20Overflow.md ExploitThird Party Advisory
https://vuldb.com/?ctiid.349221 Permissions RequiredVDB Entry
https://vuldb.com/?id.349221 Third Party AdvisoryVDB Entry
https://vuldb.com/?submit.755341 Third Party AdvisoryVDB Entry

Track CVE-2026-3613 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.9CVE-2026-3703Wavlink wl-nu516u1 firmware memory buffer overflow vulnerabilityA flaw has been found in Wavlink NU516U1 251208. This affects the function sub_401A10 of the file /cgi-bin/login.cgi. Executing a manipulation of the…EPSS 1.2%7.4CVE-2026-4861Wavlink wl-nu516u1 firmware memory buffer overflow vulnerabilityA weakness has been identified in Wavlink WL-NU516U1 260227. This vulnerability affects the function ftext of the file /cgi-bin/nas.cgi. This manipul…EPSS 1.1%7.3CVE-2026-3612Wavlink wl-nu516u1 firmware injection vulnerabilityA vulnerability was determined in Wavlink WL-NU516U1 V240425. This affects the function sub_405AF4 of the file /cgi-bin/adm.cgi of the component OTA …EPSS 10%7.3CVE-2026-2615Wavlink wl-nu516u1 firmware injection vulnerabilityA flaw has been found in Wavlink WL-NU516U1 up to 20251208. The affected element is the function singlePortForwardDelete of the file /cgi-bin/firewal…EPSS 7.8%7.3CVE-2026-2567Wavlink wl-nu516u1 firmware memory buffer overflow vulnerabilityA vulnerability was detected in Wavlink WL-NU516U1 20251208. This vulnerability affects the function sub_401218 of the file /cgi-bin/nas.cgi. Perform…EPSS 1.1%6.6CVE-2026-2565Wavlink wl-nu516u1 firmware memory buffer overflow vulnerabilityA weakness has been identified in Wavlink WL-NU516U1 20251208. Affected by this issue is the function sub_40785C of the file /cgi-bin/adm.cgi. This m…EPSS 0.99%5.1CVE-2025-10961Wavlink wl-nu516u1 firmware injection vulnerabilityA vulnerability was determined in Wavlink NU516U1 M16U1_V240425. This affects the function sub_4030C0 of the file /cgi-bin/wireless.cgi of the compon…EPSS 8.1%2.1CVE-2026-8227Wavlink wl-nu516u1 firmware command injection vulnerabilityA weakness has been identified in Wavlink NU516U1 240425. This issue affects the function wzdapMesh of the file /cgi-bin/adm.cgi. This manipulation c…EPSS 8.5%

Source: NIST National Vulnerability Database (record CVE-2026-3613), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.