CVE 8.7 HIGH

Wavlink WL-NU516U1-A POST Parameter wireless.cgi sub_407504 stack-based overflow_CVE-2026-13539

8.7 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P

Description

A vulnerability was identified in Wavlink WL-NU516U1-A M16U1_V240425. The impacted element is the function sub_407504 of the file /cgi-bin/wireless.cgi of the component POST Parameter Handler. Such manipulation of the argument Guest_ssid leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used. It is suggested to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

AI Analysis

Stack-based buffer overflow vulnerability in Wavlink WL-NU516U1-A via manipulation of the Guest_ssid argument in the wireless.cgi file

Basic Information

ID CVE-2026-13539
Source VulDB
Published Jun 29, 2026 at 05:30

Affected Product

Vendor Wavlink
Product WL-NU516U1-A
Version M16U1_V240425
Affected Versions Wavlink WL-NU516U1-A M16U1_V240425

CWE Classification

AI Assessment

AI Score 8.7 / 10
AI Severity High
Vendor Wavlink
Product WL-NU516U1-A
Version M16U1_V240425

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.